Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T173F11FF1E040ED3B035386C5A7BA6B5F7791C349CB030A4553F883AB6BCAC60CE25599 |
|
CONTENT
ssdeep
|
96:Tk8nbzD71tDlt8v67McdsSS8LytGWFV+XBHF+KXtX/DtF7gtR6Dd2J:Q8nbzD715lt8iIGRyk5vXLj7g7sdw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e4e41b9b186c935b |
|
VISUAL
aHash
|
fff3f3f3ffff0000 |
|
VISUAL
dHash
|
002626a626000600 |
|
VISUAL
wHash
|
ffc3c3c3c3ff0000 |
|
VISUAL
colorHash
|
07000000030 |
|
VISUAL
cropResistant
|
00062626a6261006,def833dce869dc7f,0000000000000000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 59 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)