Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T148149D33421935270537C6D430B95B37D2A6DE4FFAA70A010FECD7EA2BE9CA0755A11A |
|
CONTENT
ssdeep
|
1536:htsEJPjQBq1Wixx2bTrIvt8VPB6RxknNucRGcOxp:zLqVfCQ6RcOxp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c339bcc2cb127c39 |
|
VISUAL
aHash
|
ff7f0074707424f8 |
|
VISUAL
dHash
|
c99bc7c9cacdcd12 |
|
VISUAL
wHash
|
ff03007c707464fb |
|
VISUAL
colorHash
|
02002200400 |
|
VISUAL
cropResistant
|
33d7c9c9cacdcd12,0802c9c92ac9c936,acac2cacac2cef24,9925363710889053,9643436363733266 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 55 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)