Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1180202726544ADB30183E3E6E770E76F7A86D349CA931786A2F8974C0FC6C9ACC50214 |
|
CONTENT
ssdeep
|
96:q7bPz2CvHIxhnOjVQgEBO4vRlXvC+BvlPwrRJoTB0VSmP7tcO2yJxyQP3m2:qrPPYnO34vRlSRJoTG17xv7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9a9a38394e4c6df1 |
|
VISUAL
aHash
|
3cffff3c3c000000 |
|
VISUAL
dHash
|
7179696169022800 |
|
VISUAL
wHash
|
ffffff3c3c000000 |
|
VISUAL
colorHash
|
070010001c0 |
|
VISUAL
cropResistant
|
7179696169022800 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 22 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)