Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D41296B2D040AC930E13D6FDF256274AF443C11DCEE3AD0586DDD79A0AF9CE2865A1B9 |
|
CONTENT
ssdeep
|
192:F0h3sOzHlpNtdma+y4Kq4GxI6eZYaaFF0/V8YQ9D9eEo:uh35zFpNtdma+y4Kq4GxI6aYaD/m7heJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bf3e70610f4f6160 |
|
VISUAL
aHash
|
00ffffbfffffffff |
|
VISUAL
dHash
|
3030286860000020 |
|
VISUAL
wHash
|
000707073f3fff81 |
|
VISUAL
colorHash
|
074000001c0 |
|
VISUAL
cropResistant
|
3838286800402060,0000000000000000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3922 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)