Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E2328433A600DC298DABA1C8F1C48689615DD345FB3108C6B1B491FF7BC9CF169A97AD |
|
CONTENT
ssdeep
|
192:iYcEcs7ejrq6tBgxaEMcnthWeNWbMl4b/fMmUU8VCo4T:FcEcs7ejrq6b4yzfMmUFCoo |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9dc94a7623762276 |
|
VISUAL
aHash
|
191b1b1b03060607 |
|
VISUAL
dHash
|
b3b3b2b27ef6fcfd |
|
VISUAL
wHash
|
191b1b1f0f0f0f0f |
|
VISUAL
colorHash
|
00000000038 |
|
VISUAL
cropResistant
|
9b5ab66c9870c081,e2c0e2b2a8315ada,b9b1b17b6ffafef4,6c68d8b060c00006 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)