Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19ED3C57251C4643A02A7C3D1B1A4A61BF0C3F14ACEC21DC896F55F6C4BE2EA1749D67B |
|
CONTENT
ssdeep
|
1536:GCJugFj8T1RTigCtH6QZlW3fl71CQneFl77VP7zK/qmjweeZeH45erTjHC3BBDCW:DBloHCRybjoJF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ace5131a93e33cc3 |
|
VISUAL
aHash
|
fff3f3f3df000000 |
|
VISUAL
dHash
|
1216262631373534 |
|
VISUAL
wHash
|
ffd3f3f3df000000 |
|
VISUAL
colorHash
|
06000006000 |
|
VISUAL
cropResistant
|
1216262631373534,0d1f5f4d4d1252f8,15333371ccd02c2c,e0745d5d19593387 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 937 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)