Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BDF20D36A4449D3F11D7C2D2A7B0BB1EF2CAE245DA9B1716A3F4831D17C7E90CD22962 |
|
CONTENT
ssdeep
|
384:bMAwAMmG0cdO+ISLcuD82looXP34/xdLDnJwbvAFQDqSIyEeNO3v2qGVqT3X:QAwHmj+IsXooXP3nqSxw3vppT3X |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d66dc91699359a45 |
|
VISUAL
aHash
|
ff000000000000ff |
|
VISUAL
dHash
|
33c28c4cc4cccce9 |
|
VISUAL
wHash
|
ff704604762604ff |
|
VISUAL
colorHash
|
39000218010 |
|
VISUAL
cropResistant
|
700d004b43434300,4041800929815040,002004787272300c,c2c41cc4ccccdc69 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 14 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)