Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T170042CF067C4AC93667342A3B09A534FA2E50606E64ECD647B1CD94913CFC5B8673AE3 |
|
CONTENT
ssdeep
|
3072:ZLTmRUu1p9Wm+OywVJ5frXjUMAL98n0d0++v:o1p9Wm+OywVJ5frz458n0d0++v |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ee6f1b4e51c54541 |
|
VISUAL
aHash
|
0081f3fffdb7ffff |
|
VISUAL
dHash
|
632707262367e498 |
|
VISUAL
wHash
|
000081f3f193ffdf |
|
VISUAL
colorHash
|
070020000c0 |
|
VISUAL
cropResistant
|
c2c2c2b2f2b2c2e2,2727e6272326c890,72e22d6527272727 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)