Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A853837060845A7B035742E8A67A5F5A73A3C396CE3307097BF88B6D5FD3E11DE2A412 |
|
CONTENT
ssdeep
|
1536:ZLOw194oNwy6b1p4cA6J57cENDxZvUjdYmJ+b:V6Zp4cSdYmq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b0d44ad1b6d5e21e |
|
VISUAL
aHash
|
7e00066f6f660001 |
|
VISUAL
dHash
|
9428c48ecc8e8209 |
|
VISUAL
wHash
|
7e0007ffffe70001 |
|
VISUAL
colorHash
|
38003000081 |
|
VISUAL
cropResistant
|
9428c48ecc8e8209 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 49 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)