Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T135B3B7737129343F235786D0B726676A729AC24ACD82079697FD83B94FA3CA0FD17448 |
|
CONTENT
ssdeep
|
3072:J1YwprqG+TrqGapK/6qpK/6orpK/6gq8ABYwS:yq8AU |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ba3bc7cac0c878c6 |
|
VISUAL
aHash
|
fd8783878787ffff |
|
VISUAL
dHash
|
212b3b1b393b6c42 |
|
VISUAL
wHash
|
dd0301838381ffbf |
|
VISUAL
colorHash
|
06240009000 |
|
VISUAL
cropResistant
|
212b3b1b393b6c42,212d2d2d65393b39,9b870d1f9129351f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 93 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)