Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T168412F1056889927835352D8FFB22E5A73D08781C79A5F1037F9C7AA5FC2E69CC4A015 |
|
CONTENT
ssdeep
|
48:RZoxmK6YDjgGHzodTk6TDoxos/v4wUf0+FhaQdqKx:4XjMhEOqv4BM+CQdrx |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a2b359cc4ef11999 |
|
VISUAL
aHash
|
ffe7e7e7e7ffe700 |
|
VISUAL
dHash
|
a8cd5d4dcd968eb0 |
|
VISUAL
wHash
|
7f67636767434300 |
|
VISUAL
colorHash
|
00000038000 |
|
VISUAL
cropResistant
|
a8cd5dcdcdaa8e8c,f08486c665236973,376174f2b6c57117,6114617171608661,102432b220240000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 73 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)