Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E4033F76A048AE3B01D782C6B7707B0EF2D6E246CA97175593F4835D07D7ED0CE229A2 |
|
CONTENT
ssdeep
|
384:bM8dHMmG01eO+ISsciW82udbEdyRbZesXZuyFIGCEfeqPo//Jjg8hLsfsw6JK5IC:Q8dsmJ+I2Idgy5VXZmJjg8E6JKA530 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d66dc91699359a45 |
|
VISUAL
aHash
|
ff200000000000ff |
|
VISUAL
dHash
|
73c2844cc4ccccc9 |
|
VISUAL
wHash
|
ff704684760604ff |
|
VISUAL
colorHash
|
39000210010 |
|
VISUAL
cropResistant
|
708f004b43434040,4041800929815040,002004787272300c,c2c40ccccccccce9 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 14 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)