Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16D05867202D8A37E062B87D89F37D92463FA45CBEBA78AC4465DC7F15476CD2E02A4C4 |
|
CONTENT
ssdeep
|
6144:Ju9ywSHPzeqd5mSq3X2vUETrwcaWT8eC1K2wE:Juypy3X28wR8L |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bfc01dc03f606ed8 |
|
VISUAL
aHash
|
ffff0101ffff8f0f |
|
VISUAL
dHash
|
c1e0535b58813838 |
|
VISUAL
wHash
|
791e00013f7f8f0f |
|
VISUAL
colorHash
|
07c00000000 |
|
VISUAL
cropResistant
|
c1e0535b58813838,8a0ace8eaafe8ec8,8092929696969694 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 56 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)