Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13B819541506C1F3762438898B4A13F4B17E846C98702AF1CEFB855ED9ECFF64D92218A |
|
CONTENT
ssdeep
|
96:PnB/L48Ydf9v5y38TNuzduhkD1zkLYdwdDd/VkL93Nh4:PBgdf9wzUm4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
989cc9336767564c |
|
VISUAL
aHash
|
ffff1e0000000000 |
|
VISUAL
dHash
|
f0f0f070f8f8d86a |
|
VISUAL
wHash
|
ffff7f08000000ff |
|
VISUAL
colorHash
|
13c00010000 |
|
VISUAL
cropResistant
|
30e0e4e4e4e4c0c4,02485a6332000000,f0f0f070f8f9d86a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 36 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)