Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C7B396627623683A206F62CFD11B170D51C2EBCBDB5257F671F0421896F9D90BEA32D8 |
|
CONTENT
ssdeep
|
1536:cPIvgluaYQNVcoMsk4S9l6x3iOZEFTKt4gL5Jp9eb5qURyjQMs4cObs9kC2+rdJX:yc03F+3H1rwch |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e69b64cc93cc19cc |
|
VISUAL
aHash
|
ffe7ffe7ffd0d000 |
|
VISUAL
dHash
|
0f0d0c0c070726c6 |
|
VISUAL
wHash
|
ffe7e7e7e1c00000 |
|
VISUAL
colorHash
|
07040c00000 |
|
VISUAL
cropResistant
|
0f0d0c0c070726c6,9381e36585c70333 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 636 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)