Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A5F2C897314815E5C2B38FD8981125447286EA9FC9718370C2FC4E3A2BD29A6778DF7E |
|
CONTENT
ssdeep
|
768:U/Orw/Or//Or8IsR9f4g3hscY7UUjJoxts1DRG:U/Oc/Oj/O4IsR9f4gRi7qs1D8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d2a55a27a558ad72 |
|
VISUAL
aHash
|
e7efe7ffe7fcfcfc |
|
VISUAL
dHash
|
0c0c4d140c4c6008 |
|
VISUAL
wHash
|
00e7e7c3c3c0b0f0 |
|
VISUAL
colorHash
|
07000018180 |
|
VISUAL
cropResistant
|
0c0c4d140c4c6008,49485652504caaee |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)