Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16BB29730D8877A3722B313C19743D72FE6C48244D11B8ACAEAF987595BC6E85EF26315 |
|
CONTENT
ssdeep
|
384:IG3AJnF20LDmytIagC7bpaFLI5f+N0GAtFhc:IBFFDmaggpaFLWiA7hc |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b31f0c3434353d97 |
|
VISUAL
aHash
|
00ffefc3e7c3ff18 |
|
VISUAL
dHash
|
86e8541c4d55ccf0 |
|
VISUAL
wHash
|
00ffe7c30303ff00 |
|
VISUAL
colorHash
|
00030000000 |
|
VISUAL
cropResistant
|
c850564c4d55cce8,2161d35b2cfd5155,828196eac6968140,7975e8580f73d039,4c0d0cb2b2320c21 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 16 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)