Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10E73B77B5484757E2BF3A2D8FB187A0EA15D4009CD26C7F4A3D6C38D25C2EA1CA7958C |
|
CONTENT
ssdeep
|
768:Is8YB2CmMgLFHHfRxi1U1DqsFKevl+bNqoyJNU5jsgmej3Gu8SCyEfh:Is8kUpxi1W14evXOsdejP8SCHh |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
875aa5d670a55a87 |
|
VISUAL
aHash
|
000000003c3f3f07 |
|
VISUAL
dHash
|
d4716992e969f6d7 |
|
VISUAL
wHash
|
060018187c7f7f7f |
|
VISUAL
colorHash
|
31006000000 |
|
VISUAL
cropResistant
|
ea80c11517c180b2,a280414d4d4180a2,2dacac4dadae6eae,d4716992e969f6d7 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 120 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)