Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C8B2963432941A7FA1C7C7F1E770377EE1A5C78ADA179A09F2E982195BC2C48CD563A0 |
|
CONTENT
ssdeep
|
192:/D5hyTMzgE9Rn3RsLqmwAz1Waz4/CrnMDkjCJz4CHgkEY5QZrgZtT+:d7913mnwQz2B/bogZtT+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fb3bcc50e168803f |
|
VISUAL
aHash
|
ff0001646e0480ff |
|
VISUAL
dHash
|
396949d9dc8d2134 |
|
VISUAL
wHash
|
ff8001e4ec2c90ff |
|
VISUAL
colorHash
|
06c03000000 |
|
VISUAL
cropResistant
|
39393038393b6969,38bc66767c7cfcfc,226ba1b46c0494a6,12928ca6a4a8cc04,3424342455545534,386959c9dcdc2930 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 96 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)