Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DD74EA3D7300D63E3223865EF0A5A395E28F7A5AC91F48A5D3FCD9839B99CE1C513A44 |
|
CONTENT
ssdeep
|
3072:kDpVNY0YcX7YulF4qUb1gcuuJ7z+xCkpaYCOaYgaYBcraYKvaYSaYyTaY7mwPOSm:kpx4ZKFyzltQ20Mgwy |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
981ea761c81dbf61 |
|
VISUAL
aHash
|
ff000018400000ff |
|
VISUAL
dHash
|
bc9d39b191bc391f |
|
VISUAL
wHash
|
ff010d1cfc0405ff |
|
VISUAL
colorHash
|
1b030018000 |
|
VISUAL
cropResistant
|
bc9d39b191bc391f,9c9e1c3090983c7b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 67 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)