Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T105D112718A083A2E92335ED0EA7563AB62ABB37DF58F101095BD43F087C6F84C927585 |
|
CONTENT
ssdeep
|
96:T+fmKjKp+36BDLQRk1ByG/I83mb2zW+L6Sk1aq6vSm1OofPez:SfmKjKwkDsRMZ/v3TLicq6hZfPK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b3b38c8c9999b926 |
|
VISUAL
aHash
|
ff67e76e24180000 |
|
VISUAL
dHash
|
62cc4cd84c100000 |
|
VISUAL
wHash
|
ffe7e7ee66180000 |
|
VISUAL
colorHash
|
07007000000 |
|
VISUAL
cropResistant
|
62cc4cd84c100000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 900 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)