Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1553373735208A53A0273C2C875752B3FE693C61ED6A30D0597EC879E2BC6D9C9D2B21D |
|
CONTENT
ssdeep
|
768:zO9twJ3wlJhBqPzQpYbGliROSMDuoBO7siClT:LtwlJhQPb6rSKBOyT |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b115c66a1d6e3b94 |
|
VISUAL
aHash
|
002e0e0e0e81ffff |
|
VISUAL
dHash
|
98dc1818181b1733 |
|
VISUAL
wHash
|
006e0e0e0e81ffff |
|
VISUAL
colorHash
|
0b0c0002000 |
|
VISUAL
cropResistant
|
dc181c18181f0633,929203d8dc9c9858,2d4949399d9dc101 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 254 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)