Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C44362B26146197F8AC791C9AF755B4EE2CBD34BC6220D49B3F2835A9FC2D60FC49610 |
|
CONTENT
ssdeep
|
768:wYBZ8f5Z8fOp2tPXSpmTtDDnkFzRyZ7viJBJBse+fZHzaDbcduhsty0gKIBKen8h:ZPbD0fI/5Pl |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bfbc5e40d8416371 |
|
VISUAL
aHash
|
12ffffffff000000 |
|
VISUAL
dHash
|
34264e5667ccc445 |
|
VISUAL
wHash
|
02bfffffff000000 |
|
VISUAL
colorHash
|
1e600018000 |
|
VISUAL
cropResistant
|
36366e4e5e5776af,0b2494e4e4142262,172f6f3fbf7d3739,26ccc8c4c8e44549 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 93 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)