Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14B43F9EA3C98B4565BA291D3B0AF364BF33A146F750C55A07060CEE570F84E9506BF8E |
|
CONTENT
ssdeep
|
768:oyWuPcNwGWyuH/tMRW/LLMX9/u8n+zU5SDCcosFLf2rzQob6Z11vjwqF/5zxLX8C:zlwyOloQzZs8oWQbp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9fd6d0c233f00f8c |
|
VISUAL
aHash
|
fcfe1f071f3fff0f |
|
VISUAL
dHash
|
cce07b0c78708070 |
|
VISUAL
wHash
|
7cfe1f070f1f0e00 |
|
VISUAL
colorHash
|
07008000e00 |
|
VISUAL
cropResistant
|
cce07b0c78708070,454523d8c4e65145 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 703 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)