Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T182E2B76043453D3FA30B8AF0E5AD73B8E1BDE385D60BA91CB77C0075178ACE89967664 |
|
CONTENT
ssdeep
|
768:pUi+JRCsscHIhPvWgdItxSD0XSN5rAr3MRF7Mk40fU+JZF4P+MjRB9+x2ZPYIL9o:H+PdZoNXG/Upvkr8HwkVk9+wJY7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ea96ca90c37a9c9c |
|
VISUAL
aHash
|
ffff8381ff8181f1 |
|
VISUAL
dHash
|
c92f330b0b333343 |
|
VISUAL
wHash
|
ffff8181e18181e1 |
|
VISUAL
colorHash
|
060020100c0 |
|
VISUAL
cropResistant
|
c92f330b0b333343,0032323232c8e802,1032303210e46804,0032303233acc801,003230303230300c,0832323232686804,0430303032505002,2c2e224182a29a92,2c2dacccccb48080 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)