Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T102731E70E091223B152389DEE675AF2AF0D3861DDB338C01F7F853AA97D7DC49A1185A |
|
CONTENT
ssdeep
|
1536:vZ6MvvIFoF7+7U7F737ZH7r7O71737Jr7qO7I7I7k7Cc7I7k7i7R767v7R7wr7Iz:0ydmiOLAboWLf |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ebc39cb6902d9269 |
|
VISUAL
aHash
|
ffe9e9e1f98381fb |
|
VISUAL
dHash
|
534bcbd3d3672713 |
|
VISUAL
wHash
|
ffe1e1e1e18181c9 |
|
VISUAL
colorHash
|
07c00000000 |
|
VISUAL
cropResistant
|
534bcbd3d3672713,c3cb272733676303,e34d465e4e6e6c79,2767978341631b3f,072b72dc8c894103 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 18 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)