Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10512C81FE396321C071B05EE796F24DF972720CCF2271A8634A9D71D72815D06B36AEA |
|
CONTENT
ssdeep
|
192:QVPFzwToKtaCa1MnlOsCRj6CPFWFX2xeYICgKuUv28MYNWgRON1r:Q5FzwToKtaCa1IWJNWRQehKuHwWTr |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a424c7c3262cdbdb |
|
VISUAL
aHash
|
0303030307ffffff |
|
VISUAL
dHash
|
6696beb6aed1c6e0 |
|
VISUAL
wHash
|
03030303037fff7f |
|
VISUAL
colorHash
|
17e00008000 |
|
VISUAL
cropResistant
|
6696beb6aed1c6e0,82aea698b9bcc931,e811888a9a9a9ada |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)