Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16C82C4F151684C2E104BA7CEF350654AD897D38FC7A15884A6FC8BFA95E1CECE4C784A |
|
CONTENT
ssdeep
|
384:iDpVfhWBD3+QWoDha8FVgvSkKRTOVOiS1Kyp45oOzbMzKyp45oOzbeDh4zAWT+HP:iDHfhkD35xDURVOi4DHZx |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a7e1989665711796 |
|
VISUAL
aHash
|
fe7f7f63373f1f06 |
|
VISUAL
dHash
|
c2e1cacee4ecf8fc |
|
VISUAL
wHash
|
783f7f23371f0600 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
c2e1cacee4ecf8fc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)