Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B6B1861BFB10225506C7016EF696A3CCD73958A8F3610A8875F9823E67E11D9C277EC6 |
|
CONTENT
ssdeep
|
96:TzdYwX7+aM8xQOUj3Q36azaBX0sBfwrId:357+QyOsA36UaB92g |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
aac4d518d2fccac3 |
|
VISUAL
aHash
|
ff030101010103ff |
|
VISUAL
dHash
|
6cdfcb3b8b8b3744 |
|
VISUAL
wHash
|
ff1f210101013fff |
|
VISUAL
colorHash
|
30000038000 |
|
VISUAL
cropResistant
|
6cdfcb3b8b8b3744 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 45 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)