Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1693395F2129006EF64D386E06E31172E6257B3B2EA4791CA76B8C31B7EC7DA0CC56651 |
|
CONTENT
ssdeep
|
768:DALgecFZELk+CuKhUgxqnidzJtJweImHkIfU7ME9AogWfP1+Np:WgecL+C6nj2p |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c46ec09c6a5e946f |
|
VISUAL
aHash
|
18000000007e7e7e |
|
VISUAL
dHash
|
3070102192969696 |
|
VISUAL
wHash
|
181800005affffff |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
3070102192969696 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)