Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16CB284769419D63B0362C6D8B3B2A78BFA419086C882854FC5F5E35C6FF2D72ED1B205 |
|
CONTENT
ssdeep
|
192:iE33/nFbOm8BKwt5Kq+v6pGrwtZUEbJk3o3531U3R3+HphuDcTBrZr:7PFCmsr5Kq+yppZUEdkYpeBOHphcIB1r |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
de7e6961e01c9e90 |
|
VISUAL
aHash
|
80809c9cffffffff |
|
VISUAL
dHash
|
31343c34341c1c30 |
|
VISUAL
wHash
|
80808c8cfeeec6fe |
|
VISUAL
colorHash
|
07008000c40 |
|
VISUAL
cropResistant
|
31343c34341c1c30 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 11 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)