Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C83352219292297B0183C9D832B3976AE3C4D604DB93C59496D98B1F4FE7CF0EDA479C |
|
CONTENT
ssdeep
|
1536:wBdTiTiDPugjgENbxhrIK6MI4njFLek4qO:wXumDPug8ENbxhrIK6MTnjFLek4qO |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec6d5393123c6e13 |
|
VISUAL
aHash
|
00c3c3c3fffffff8 |
|
VISUAL
dHash
|
f89616b6d0a2d0e5 |
|
VISUAL
wHash
|
00c181837fff7e70 |
|
VISUAL
colorHash
|
06200001180 |
|
VISUAL
cropResistant
|
929606b6c0a2d0e5,0008117171910080,5a52727297e1e171 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 58 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)