Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15A6199A255086F2E136250886297BE1931D8D2C1E7CE79005BFA52FF5FE3D24CC6A1E7 |
|
CONTENT
ssdeep
|
96:nuK9vQENl/Hj+Px5TDeQamdj5I69A6SSKS6LbkG2:b5f/HjCx5TDeQx5I6e6SSKSSkG2 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cccccc33333399cc |
|
VISUAL
aHash
|
1818180000000018 |
|
VISUAL
dHash
|
1030301000000010 |
|
VISUAL
wHash
|
dcdcdcdc00000018 |
|
VISUAL
colorHash
|
380000001c0 |
|
VISUAL
cropResistant
|
1030301000000010 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 572 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)