Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BAB1F06060289E33514781EAB3EB6E0B3591D349CF8A170447F963EE1FE7C72FA59246 |
|
CONTENT
ssdeep
|
96:I9JDmPz03oseimJBQ0oR7TAq35Jh5s3UPG35rfuwO/Yct3eXnqKvNZ:I9JCzs6n/4RBLhcUPG5GkctOVvNZ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f52996db02c7868b |
|
VISUAL
aHash
|
c3c3c3c3c3ffffff |
|
VISUAL
dHash
|
969696969650640c |
|
VISUAL
wHash
|
00c2c3c3c3fefe86 |
|
VISUAL
colorHash
|
07001010201 |
|
VISUAL
cropResistant
|
969696969650640c,6a4040109014404c,967021038b459033 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)