Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1139383F3F07019B9026B81E3E128BF9AB1C6BA45D7C445C09AE853DE97D0D60FD9249E |
|
CONTENT
ssdeep
|
768:QRD0lA9xUl7UWvWLK719DIg2/g69jHJP0YuF:QRD0i9xUl7UWvWLK719DIgaBR0YE |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a4c63bd99999c985 |
|
VISUAL
aHash
|
ffe3f7fff7c00000 |
|
VISUAL
dHash
|
1da5259406075f27 |
|
VISUAL
wHash
|
ffe0f7ff87c00000 |
|
VISUAL
colorHash
|
07606000000 |
|
VISUAL
cropResistant
|
1da5259406075f27,532321298d81d935,0312020202030304,a4842e8737cf172e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)