Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BBD294B00103CDBF2087DED0B670A2ABA49BD615CA13D75A53F6532A3ADBCD1CC95639 |
|
CONTENT
ssdeep
|
192:/Fv3pJD3N8xIkIYsJca1O4jisYxfxSJBJ9TM7ngxsfFXLfJVq0VYqy2MLZJy0r/M:tvv9+o2zmXstzPRFy2o5XwX++z5EWMQ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dbdda2d1aa66a284 |
|
VISUAL
aHash
|
9b989c9c9c988081 |
|
VISUAL
dHash
|
1330313130300c21 |
|
VISUAL
wHash
|
ff9c9c9c9c9c8089 |
|
VISUAL
colorHash
|
38000000180 |
|
VISUAL
cropResistant
|
1330313130300c21 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10239 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)