Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T154435236A080662300B745D4E73A7F6EB2E25549D6522F91E2FCC35E5BC7E82EC0916E |
|
CONTENT
ssdeep
|
1536:1CJjsJB5MtITDcL14QEOYpd5vag7a3edMZQ0UcN8BK2t6Qn2:1CJjsJB5MIfcL1JgK2u |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec9392cd3c9bc4c4 |
|
VISUAL
aHash
|
fffffb83c1f1c381 |
|
VISUAL
dHash
|
3203131b27072b37 |
|
VISUAL
wHash
|
bffff981c1e18100 |
|
VISUAL
colorHash
|
07000030000 |
|
VISUAL
cropResistant
|
3203131b27072b37,2254b4b48bc83000,3331010941052363,b242044563a36341,b28505a18448a030 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 111 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)