Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C123D83114C4AF7B41E352C4D310B60FD3968144E6AA97CFF9F6871E9BC6EC4C926A58 |
|
CONTENT
ssdeep
|
768:uqjFV0oD1tXHjzFMoxhO/dRa0y3yXnn3nOUJbluJ+2g9Lt:uqJaoD1tjzFpO/d5Tn3nY+2g9Lt |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9414ebeacacaca96 |
|
VISUAL
aHash
|
fd06060606fffff9 |
|
VISUAL
dHash
|
71ccccccec3c3313 |
|
VISUAL
wHash
|
fd060606061cfff9 |
|
VISUAL
colorHash
|
0e000000180 |
|
VISUAL
cropResistant
|
0001c96161c90162,96d6e8b294710f8e,c0303b0c33131313,b8e4c8e0f0e2e2e2,8cccccccccececec,d2f161e1e3e3c7ce |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 174 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)