Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18AB3E771B194303380174FE9FA78AF89A273F61ACF493556A6E4577423C7C71780AAAC |
|
CONTENT
ssdeep
|
1536:Y39cWQ7/lWQ2xfGXBTyQ7t3qHFC3rnW9sV9gpijcOMOgO8OEOoOMOIOMOFrj4:UaWQ7/sQhTyQ7t5W9s8p0/4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
88f3e698c29cc2bd |
|
VISUAL
aHash
|
ff00181818181918 |
|
VISUAL
dHash
|
71513333b33333f3 |
|
VISUAL
wHash
|
ff001899191f1f3e |
|
VISUAL
colorHash
|
01000000007 |
|
VISUAL
cropResistant
|
71513333b3333333,055dfdfdfdfde1fd,cc8e96eab2b22b82,a901110101010101,51333333b33333f0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 23080 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)