Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T159132425C52CE830071B73C217B55B2F72B296B9C6461FE945FA22F7274AC42B287D1E |
|
CONTENT
ssdeep
|
384:oOLZwdxHPSDh4b6C5xt9EkgmbhC5w5nHpYZ+Abb6C55wukUb6C5FaekBw6whFjO8:9m5hE5gHw55t5Fk0OUeMnlvh |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d51e1c6a63636762 |
|
VISUAL
aHash
|
001ff0f0ffff0002 |
|
VISUAL
dHash
|
6430484a88840902 |
|
VISUAL
wHash
|
000ff8f8f9ffc0c0 |
|
VISUAL
colorHash
|
07000018003 |
|
VISUAL
cropResistant
|
6434484a88820902,3434b03474744448,639898c998d8d825 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 133 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)