Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1585374375104641BC673C1E47277933AD392968AD3F30D016AFCC7AE5BC6EA48B7A219 |
|
CONTENT
ssdeep
|
768:THj3wlJhBWgT1zrJ9mEAh7k4LeCmY0Wiu0GT8Q161uh+:DrwlJhpX9wBk4LeCmYQu0G7E1uU |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9715e86a466e1f91 |
|
VISUAL
aHash
|
000e2e3e0e00ffff |
|
VISUAL
dHash
|
d898586c58190f00 |
|
VISUAL
wHash
|
004e2e3e0e00ffff |
|
VISUAL
colorHash
|
0b000600048 |
|
VISUAL
cropResistant
|
60caeaa680210044,6b6a7878605959ee,d6a62238adb6cee0,391b0e4132323333,81d858586c58581f,200c307171200420 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 254 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)