Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T192322132844B9E176847D1CAF670775E21C0D5C59B2626C6AEF85B2E3B8ACE1DC127F0 |
|
CONTENT
ssdeep
|
192:XoyDS9Erv3let3GaOn30ei2mkr6xarMTc9NRaO2G441Tp3zcs1UI0zXwB8MgmZww:XolKjl7nh1m5EYTkV2833YmVuOe4w/fw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a3a189084c5e77f7 |
|
VISUAL
aHash
|
00ffff0000000000 |
|
VISUAL
dHash
|
b08c8c3004000000 |
|
VISUAL
wHash
|
ffffff6c00000000 |
|
VISUAL
colorHash
|
07007000000 |
|
VISUAL
cropResistant
|
90888c8c8c8c8cb0,0800008080808080,0000000000000000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 106 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)