Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17752CA72A0449A7711A3D3E5E771DB2FB682C389CE831682E2F8D34C1FC6DA6CD56214 |
|
CONTENT
ssdeep
|
192:ataN/2vP7nuMCA14vRln4dcJ5B1ILVCQwawi7GAKcR9uoTG2l3lI/0:667AK5+VCQwawi7Gixlq0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9b9b3030926d6dce |
|
VISUAL
aHash
|
3c3c3c3c3c000000 |
|
VISUAL
dHash
|
7979696969680000 |
|
VISUAL
wHash
|
3c3c3c3c3c000000 |
|
VISUAL
colorHash
|
38c00008000 |
|
VISUAL
cropResistant
|
b4b4b3e8e8944006,333332dab6ba9ab2,7979696969680000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 22 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)