Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D3331B602151DE3E458383D4D764E71CE3DBE285CB5B168AD3EC832B6ACACD9FC29194 |
|
CONTENT
ssdeep
|
768:GQ6RslHHwXL3SQ5PEtWNt1+1bKZ9WVNTlHjAPwvu4:/lHHwXL35+t6t1+ITclHAAu4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec6e9394989393c3 |
|
VISUAL
aHash
|
fbd1e181d1ffffff |
|
VISUAL
dHash
|
0327032323471738 |
|
VISUAL
wHash
|
f991e18181a3e78f |
|
VISUAL
colorHash
|
060020001c0 |
|
VISUAL
cropResistant
|
0327032323471738,8200807070308082,828280b030700082,8200c03030600082,8200303070308082,a280a28c8ca280a2,a2b2b2b2b2b28e86,002980647993934e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 31 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)