Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1247353247801686630EF4ACFE273798E2284EBCAD95619D9C6F0471469F7CA1FED12D8 |
|
CONTENT
ssdeep
|
384:+WaC2zZv6D/gTqIZB4P84a7a3pGCa7a3pGDa7a3pGDa7a3pGL1ca7a3pG/fa7a3L:Mp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fa6976c8251f405e |
|
VISUAL
aHash
|
00c0c103f9fc8c47 |
|
VISUAL
dHash
|
140813d7a3d1394c |
|
VISUAL
wHash
|
00c0c103fffd9ce7 |
|
VISUAL
colorHash
|
07000038000 |
|
VISUAL
cropResistant
|
140813d7a3d1394c,00404040d0d04048,0000000080524c6c,3634343448000000,09c42b2b2bc14949,3292a25840000000,39051533366cc9a1,9929393329ad2c3d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 813 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)