Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17AA3B63594C41E3764B362CDF3C6D36BE1D5D088F446C296E2AD87BE02DCD8CE61AA85 |
|
CONTENT
ssdeep
|
3072:ApjoX0Mi9cVIDH1/snP22BZpGsGqsvKIB:ApjQ0MkcVa0P2kZpGV |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8952267cabd199d9 |
|
VISUAL
aHash
|
0000187819181a33 |
|
VISUAL
dHash
|
e4d4d2d3d3d2d2e2 |
|
VISUAL
wHash
|
00087879791f7a7f |
|
VISUAL
colorHash
|
38002000180 |
|
VISUAL
cropResistant
|
6677e6b2b8c6050f,a270ba92c2a2e0a2,e4d4d2d3d3d2d2e2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 36 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)