Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13271DCFAC3A2A4239177C6D572B6577B72D4824CCA0706A543FD43AC8BEEC51FC15984 |
|
CONTENT
ssdeep
|
96:TGu7VLUX1LNggbLKeADkhQ+lolzDHXuvs+3:aLNggbL/A8QGWzbu7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cccc993333316766 |
|
VISUAL
aHash
|
3c3c181810003818 |
|
VISUAL
dHash
|
b0f0b0b0a090b0b0 |
|
VISUAL
wHash
|
7c7cf8f878183c18 |
|
VISUAL
colorHash
|
30c00010000 |
|
VISUAL
cropResistant
|
9a294d560b1313ec,82a0939304068080,b0f0b0b0a090b0b0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 9 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)