Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D4B1DF72C2FA61270333D4C2F5B1B768A6D2005DDB63162196F91B6E5BCDC66F803986 |
|
CONTENT
ssdeep
|
96:uBX1t2ixjkiAjGMjvIJj/Zj95OFxLjc05YOGBPVe9b6pD:uZ1tvZ5s9vap/G1fWPVmA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
925b6c3433bab8cc |
|
VISUAL
aHash
|
1c3c3c2c3c3c3e34 |
|
VISUAL
dHash
|
75507078f8596464 |
|
VISUAL
wHash
|
1c3c3c3c3c3c3e36 |
|
VISUAL
colorHash
|
18000000030 |
|
VISUAL
cropResistant
|
70b3b1f0f0f1494b,71d0ccd65a9b6b4a,71594b6f33535569,75507078f8596464 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 91 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)