Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1472272F1E060EE77071782D5B77A77AB76B1C248CB420A4453F493AD6BC9DA0CE2189C |
|
CONTENT
ssdeep
|
192:QIK8e41YgZnzYEnyV5O8iIqdrXMnwyTK7NC7YX/8F:QIKQ1Ywzb8U1LVXMnwmK7NC88F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b1b14ece39b94c86 |
|
VISUAL
aHash
|
ffffcfcfcfffff00 |
|
VISUAL
dHash
|
100c9e1a1e400028 |
|
VISUAL
wHash
|
0000000000080000 |
|
VISUAL
colorHash
|
07600008240 |
|
VISUAL
cropResistant
|
10089e1e1e1c0008,31194666a6b4a0c1,0000002020202020 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 59 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)