Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CB333AF47842F5239AB3409760FF1906737E550FA80D0960E268EEDE75F485A70ABBC9 |
|
CONTENT
ssdeep
|
768:uQIT0TQH7YFUSYjxc+u86ErBOLVkAVzc+b42NB2jIGrTnzq8QE12OlDlGYQZ/y:uQocL86ErBOLVkEzQ2N0msQw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a40636b9b9b14d67 |
|
VISUAL
aHash
|
000000ffffffe7e7 |
|
VISUAL
dHash
|
d8e4e43b33070f0f |
|
VISUAL
wHash
|
000000ffffffc3c3 |
|
VISUAL
colorHash
|
12200030000 |
|
VISUAL
cropResistant
|
12a6124d4c0a92a2,1c3b33370f0f0f0f,c6d8f0e4e4e0e8f4,1111751111711131,0000000000000000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 33 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)