Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15923E0427108AA96C2F349DD9500259070C7EF4EC97087B08A791E3B27E3A7577E9B7E |
|
CONTENT
ssdeep
|
768:WY8m3MsNWaf5wv2aDD/4jobwGNt6pBQaCK1BK0zRUYluSgVnJbz3:WY8m3yafzaDD/4kbwGNt6pBQaZJQScJv |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9550ea35d32dd227 |
|
VISUAL
aHash
|
cccc0e1e060603ff |
|
VISUAL
dHash
|
989c983a983a6f0d |
|
VISUAL
wHash
|
eccc4e1e0e0603ff |
|
VISUAL
colorHash
|
07606000000 |
|
VISUAL
cropResistant
|
9c89e9f961276567,989c983a983a6f0d,cc8e8e3cbca6ae27,06233212d3d3d3f2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 5 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)