Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T131C3977280A1E53B019FB2D1A238B749E3C3834BDB5A4BD1A7FC43585BC6DA1ED23525 |
|
CONTENT
ssdeep
|
768:0+mt+qp9hmULgrXsJ+1gnqFWluaDrU0dZlU5ljzLuUE4kLHYsjH8dUjvvOYbJgZb:0+m4qp9rEQuaDrU08OVH5A+g |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e99665c394969396 |
|
VISUAL
aHash
|
db81ff9f99f98181 |
|
VISUAL
dHash
|
133333333b230b13 |
|
VISUAL
wHash
|
e381bd9d99f98181 |
|
VISUAL
colorHash
|
06000000007 |
|
VISUAL
cropResistant
|
133333333b230b13,f9d82521236462d3,02027a58193b5f19,8181544401c12121,4d0ccc0c4dc94c4d,7711919290711111 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 540 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)