Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F2926570734026778693C771B6107BB9E2FCC689D61BC969F2E8815A27CFC358B617A0 |
|
CONTENT
ssdeep
|
384:Jsy+g2k2626t2o2YEyUaj2Wojf3IPgtqjOOOhrOIivefX9Kf46fmlfOfb34KBgAc:+zg9x/h5EyUe2Wa4P9jOOOZOBefXUf47 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ccc3333c31dbcc31 |
|
VISUAL
aHash
|
4030383c18381000 |
|
VISUAL
dHash
|
c064e071f0a06218 |
|
VISUAL
wHash
|
7e38787c7e7e2200 |
|
VISUAL
colorHash
|
38e00000000 |
|
VISUAL
cropResistant
|
c064e071f0a06218 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)