Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1268386347901686630EF85CEF273798E2284DFC6CA5619D9C6F04724A9F7CA1FE912D8 |
|
CONTENT
ssdeep
|
384:jpPzFNX0H7/fTt/ZjM4a7a3pGga7a3pGrJa7a3pGJwa7a3pGR2S1ca7a3pGQa7af:ijXuyWp6DC3vgVJBXo9 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b96c3b681ed0c5d8 |
|
VISUAL
aHash
|
8181fbfbfbfb8d05 |
|
VISUAL
dHash
|
2b2b923223131929 |
|
VISUAL
wHash
|
0081fb9bfbf18d05 |
|
VISUAL
colorHash
|
07400030000 |
|
VISUAL
cropResistant
|
2b2b923223131929,c10323332b0b1327,374f830b01231343,13030b95132b6968 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 726 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)