Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1490231D1C558983B03529AD4BBBCBB4F7352C38ADF070A4463F4536BEBDACA48A1145E |
|
CONTENT
ssdeep
|
192:QBtRth4YnzH0LFWiEgTi79Xsd2C2Rd2C2v61J:QBfX4YzeWXoiSd2C2Rd2C2vY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b130e718cec78ecc |
|
VISUAL
aHash
|
0f0f0f0f0f0f0f3f |
|
VISUAL
dHash
|
1e9e9ede3a9ada78 |
|
VISUAL
wHash
|
0f0f0f0f0f0f0f0f |
|
VISUAL
colorHash
|
07002000041 |
|
VISUAL
cropResistant
|
1e9e9ede3a9ada78,71d4b28686b6d471,89094d696d2d9d48,1771d4a484c47117,6b6b3395d5cccc8c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 59 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)