Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B1812FBC40401DFBB133CA936594B319D4B6933DDF421801CEF667A8BAF1C8AA9E8459 |
|
CONTENT
ssdeep
|
96:p+bPYUhYHj3x2+sG4XL7M4OhMYQGWIXy1z4lrvo:pIF2j3x2rNaNQTX4lbo |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8ca733898ca699bb |
|
VISUAL
aHash
|
ff00001818180000 |
|
VISUAL
dHash
|
1100103030100000 |
|
VISUAL
wHash
|
fffef8f838380000 |
|
VISUAL
colorHash
|
00007000000 |
|
VISUAL
cropResistant
|
1100103030100000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 28 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)