Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T167D3E77190C0343B83B783D172A8A61BF1C2F189CF821AC996F65B5C4BE1D91746D6BE |
|
CONTENT
ssdeep
|
1536:6IlG+baY1RTd34nK6PQ5iOQneFl7rVB5j4F7i9AeeLw34LehT0ZytBB9Ar5L+3J4:rBNCZyNQD04mU |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ece11292e33c936d |
|
VISUAL
aHash
|
fff3f3d3f39f0000 |
|
VISUAL
dHash
|
4a23272723353731 |
|
VISUAL
wHash
|
fff3d1f1f3910000 |
|
VISUAL
colorHash
|
06000006000 |
|
VISUAL
cropResistant
|
4a23272723353731,84842cccca92c383,6a39292a2c246224,15333371ccd02c2c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 937 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)