Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F224D991330006EA8957C3C4FA523E19A166F3A9CB77EC59FEED89518BC7CF8E811194 |
|
CONTENT
ssdeep
|
768:fZ7ZZZdZBIi3UwDTgJOnD7qwWdIPzbqzyvrIpzmFYi3wwLf/HycqhF+qnmFYi3wC:fh3bjnvrIpeppG+37plnTAmB/q8+6/Xd |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8af2750d370d570d |
|
VISUAL
aHash
|
fffffffd19000000 |
|
VISUAL
dHash
|
34193169697b7353 |
|
VISUAL
wHash
|
fffdfffd09000000 |
|
VISUAL
colorHash
|
13c00000000 |
|
VISUAL
cropResistant
|
3615199931314969,0073563030341656,19b97169e9737353,9c9cb4253d3d272f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 191214 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)