Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CC621E377045823A0E9B52ECEB8CB369A28D814AF734C48255F5817FAE91DEC743536E |
|
CONTENT
ssdeep
|
384:fKIy0kyXyBG8hOZ22PAvQYq5ZVp57HUccwst2YUgCfMmUFCoj:yxuyBG8sZ22PAvQYq5ZBbUccwst2npf0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
916e6e99e1d2906d |
|
VISUAL
aHash
|
f9000e6f0f0f0061 |
|
VISUAL
dHash
|
0338fc989a9c1ccb |
|
VISUAL
wHash
|
fb000eef0f0f0c67 |
|
VISUAL
colorHash
|
394010000c0 |
|
VISUAL
cropResistant
|
fca4a492f2d2c7c3,0000000000020400,60c4c48480828281,0338fc989a9c1ccb |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)