Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T185F3A643419C1A7A18A746C28504572FB4C4914EEF5E9AE9E1FBC3B912DACD0BDB36C3 |
|
CONTENT
ssdeep
|
1536:Cq99l9Qa29BZVkuFzrgntr+1ixexO1Vafu0D1NZSV8sh/qzJCo6/cr7D/KkCCw40:E2uR8kCHMupy4zmoxKXjRd0T |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ba63c2786e6a7069 |
|
VISUAL
aHash
|
81e7e78181dfdfdf |
|
VISUAL
dHash
|
0b88cc0b33b2b2b2 |
|
VISUAL
wHash
|
81e7e78181c3c3db |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
0b88cc0b33b2b2b2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)