Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DB2364A17E136822329F82CF925B260C60D1E7CCE94235D5B9F4C37466B6CE1FBD16A4 |
|
CONTENT
ssdeep
|
1536:YII1c4ueBSX/nXvpKK8lfQV4mlBWE6rUe:YnBSPnXvpKK8lfQVvWE6rUe |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d6542969153e6e35 |
|
VISUAL
aHash
|
00fefefcfcf0ffff |
|
VISUAL
dHash
|
84082c2c0401230c |
|
VISUAL
wHash
|
00f084e4e0e0ffff |
|
VISUAL
colorHash
|
06203010000 |
|
VISUAL
cropResistant
|
802c2c2c00013a0c,0196869496069900,13920884b6961272,cb1053500e0d8f4d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 937 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)