Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A8C4B7E2E9389D35102756F1D3D7B6D537D8F281C7A00984C3EC2351AAEDEB01663A6E |
|
CONTENT
ssdeep
|
3072:azDfHLjvPLjALjvPLj0qK2+iCBqK2+iCd55dlBhI55dlBh1368K3Y3xUX2uIi0I6:afl55dlBhI55dlBh1368KQxUfIi0I6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bac5c590d03ec53b |
|
VISUAL
aHash
|
ffbd8181818181df |
|
VISUAL
dHash
|
e961393939313939 |
|
VISUAL
wHash
|
ffbd8181818181ff |
|
VISUAL
colorHash
|
076000c0000 |
|
VISUAL
cropResistant
|
e961393939313939,b5362e8a4a4a76b7,e0ac383c34307434 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 26401 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)