Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15822627193A5792302A382C1AB766B6B73E18248D7530B0163FCC36EAFCAC96DD131C5 |
|
CONTENT
ssdeep
|
192:QZfPSsDXr0UQuNvzuEKVu+OiZRW7vPew5aXgT:GfLDN1KBVRTcHew5ag |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ca90b56bd7947289 |
|
VISUAL
aHash
|
c1f3febc3880dbfe |
|
VISUAL
dHash
|
13ab4d61410533a8 |
|
VISUAL
wHash
|
81c3fcbc38009bfe |
|
VISUAL
colorHash
|
07000038000 |
|
VISUAL
cropResistant
|
13ab4d61410533a8,232b2bd4d4d45444,2b2313276e6e2713,b210686c0230344e,1f3e3f7b333b9ef3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 24 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)