Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T123E2657B54856A3F229B82C6F6707E0DE2DAD64AC7531A9673E4830D43E3EC0DD31962 |
|
CONTENT
ssdeep
|
768:6EloPJ5Bru+IvuxbzVK2JF18v9MC7RqDj0MCvq:Mx5Bru+IEzVK2JFOvj7RqDQMCi |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c7b9b8c6bcb24941 |
|
VISUAL
aHash
|
fffd000030342400 |
|
VISUAL
dHash
|
23d3d26cecccccac |
|
VISUAL
wHash
|
ff7c782036767600 |
|
VISUAL
colorHash
|
39200618000 |
|
VISUAL
cropResistant
|
02005b6323430001,f48c16565a9280c0,0020046871700c20,d0d36cece4ccccbc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 14 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)