Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B2B19731505D4C6FD082C3C893F5732B62CA9195DFDF0A19E2E9871D99DED81EC2A2B8 |
|
CONTENT
ssdeep
|
48:TTg1kwk5k72Y4ApW2U30filetAmxoWqk57Dq8oHjoFJjzYdoR7qX80gFs4tQEIDC:TnwvQ2J0GAHMFJvfZPFs4tQ1+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b938c6c7389a3939 |
|
VISUAL
aHash
|
ffff8f8f8383ffff |
|
VISUAL
dHash
|
18e51a181b1be41a |
|
VISUAL
wHash
|
fef001050000fbff |
|
VISUAL
colorHash
|
070000081c0 |
|
VISUAL
cropResistant
|
18e51a181b1be41a,9f9eaced9d94a1b3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 34 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)