Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AD3111B010415D374743C2D4A3E7BB1E71C2C247CE4B2501C2FA97ED1BEAD11DE095AA |
|
CONTENT
ssdeep
|
24:hnCMhrdTN34aAh4Vhen9dUA16VkVb+iN9uENITuI+F3dL5Mm+/sEHWD6Um:LPTNox+VhUUC8WHxGuhSTsEI6t |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a61e0707cf719d07 |
|
VISUAL
aHash
|
270707072707072f |
|
VISUAL
dHash
|
6f6ffeadeddcdddc |
|
VISUAL
wHash
|
2f0707672707073f |
|
VISUAL
colorHash
|
0e600010000 |
|
VISUAL
cropResistant
|
ddddfc9d9d3c3d2d,1989a080c0f03c4c,ccd4f2e0e0b03667,a0908817232580a0,129a96927365e565,7236230c0c1a080d,31271b4482c00707 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)