Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12613C73118D46F6B919392CC9310765BD399854CE2B6894AF9DEC31A1BC5FC9C83BF88 |
|
CONTENT
ssdeep
|
768:EcoqS9k/RdemPNibBLfA9YkqZv1Zs+cReRkiUO/DuYX8Eqn9DiNBKX+Y2ih:EcoqS9k/RY1fA9AZv1ZYdpO/SUeIKX+4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9414ebebcacac896 |
|
VISUAL
aHash
|
fd06060606fffff9 |
|
VISUAL
dHash
|
61cccccccc1c1b33 |
|
VISUAL
wHash
|
fd060606060efff9 |
|
VISUAL
colorHash
|
0e000000180 |
|
VISUAL
cropResistant
|
0021896161890162,96d6e8b294710f8e,c0181b2c63731313,cccc8cccccecccec,70b4b49696f2ebdb |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 174 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)