Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T138629532A9A4593F5187C2C5D769673E73E6C28AD7431210A0FC97AC0B96C93DE37A60 |
|
CONTENT
ssdeep
|
192:Um6cfcvOCaiCKwn2NasWTR5Ek1rbsgqLs0S:UakAKw2Nas0571rbsgUfS |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a2b33ab692b23ab8 |
|
VISUAL
aHash
|
8f83837163134700 |
|
VISUAL
dHash
|
3e0f0fc3cbe68f1d |
|
VISUAL
wHash
|
8fc383f373374700 |
|
VISUAL
colorHash
|
01000180000 |
|
VISUAL
cropResistant
|
3e0f1fc7cbe6ef9f,0baaacb751c989a5,1f0b6bd4d7d51b3f,b34db7b2b2b44b35,3f491a9aaa3a363f,3f5b97a5afad3d6f,8080a09a888080d0,3e070fc3c7e69f19 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)