Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T116E1D8E3914C60091222DAC0B9C2FA84B277CE07CB5D5836F5B660A7B6DEAF4C177752 |
|
CONTENT
ssdeep
|
192:wWN1pUmWN1pUW+FOvyAiGYVmg1ldyZgZEd58dPVIq:wC1plC1pvxyASmyldyaW/8dtr |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a258f3741cb79c26 |
|
VISUAL
aHash
|
0000000700ffe7ff |
|
VISUAL
dHash
|
a983f9ecefcecece |
|
VISUAL
wHash
|
00001d0701ffffff |
|
VISUAL
colorHash
|
030020001c0 |
|
VISUAL
cropResistant
|
a983f8ecefcecece,512c2a492989a193,16080be4e4138000,0000002000040484,ffffffffffffffff |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)