Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15243124271486AA9C2F345C8940439906087EF4ECDB4C7B05AA81E3727E3BB66795F7E |
|
CONTENT
ssdeep
|
1536:XKuAsM81NGXm3oHbnCO48tTENVdQoJq/WoKg4a:XKuAslEE/6O6H |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b0894cf22dd2adf2 |
|
VISUAL
aHash
|
ff4fc7c7c7c7c400 |
|
VISUAL
dHash
|
92989e1f9f0e8c8e |
|
VISUAL
wHash
|
ff4f8783c787c400 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
92989c1e9f1f0c8c,929c1e1f9f0c8c8e,ededfffffcf0f3f1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 5 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)