Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19BE2A7F19055123F5963D3C0A6D67B18BD83C025CAA156C09AFC879C87E7EF3E19223A |
|
CONTENT
ssdeep
|
768:UjhEFgqST8kK/8lz3dM2o1g/9mT9Cn/7Mc9AMHO8:yEFgH8kQcz3dHo1g/9mT9MDJ9AMHO8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d6c8583233b3d31b |
|
VISUAL
aHash
|
c8f8ffffb4000000 |
|
VISUAL
dHash
|
9831e0cc282c2c68 |
|
VISUAL
wHash
|
ecf8fffff6000000 |
|
VISUAL
colorHash
|
07206000040 |
|
VISUAL
cropResistant
|
8810b1e0cc4e28ac,66c4c3d8d9d8dac6,838381130206040c,0800206342660400,662cac6daca9286c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 51 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)