Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11923C97158C82F2BD59342C8D3205A4BD3958188E367864EF5DE871B6BC9D96C83FF88 |
|
CONTENT
ssdeep
|
768:h2eI5m2uTgTYu2/iYxIm1r/3TMG1b+49adO/OaOMRHumKr6/rLp8vqVG553dEJFL:s5m1ES/iY2m1rvYGF/adO/S8Se/npKNa |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9414ebeac9cac996 |
|
VISUAL
aHash
|
fd06060606ffffff |
|
VISUAL
dHash
|
71ccecccec1c3833 |
|
VISUAL
wHash
|
fd060606060cfffb |
|
VISUAL
colorHash
|
0e0000001c0 |
|
VISUAL
cropResistant
|
0021896161890162,96d6e8b294710f8e,e0181c2d2c6b1313,ccccecccccececec |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 174 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)