Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AEF3A4F3E2B5443A033B91D4A1717BC9F4C7B646CAD106E4B3F492AC9BD1DA0AA4794C |
|
CONTENT
ssdeep
|
1536:MkHdH478o0n0RWyCEYjyXu68kNJKNbihyNcZpkx:gk1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e61c98c993d989b6 |
|
VISUAL
aHash
|
ffa3e3e3e3e3e3f7 |
|
VISUAL
dHash
|
7527264e4a4247c7 |
|
VISUAL
wHash
|
ff0081e3e3e1e323 |
|
VISUAL
colorHash
|
06c00040000 |
|
VISUAL
cropResistant
|
7527264e4a4247c7,e0f19d99d8947061,1e66737b63f3cf9e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 164 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)