Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C163CEB1520014AE0BD3F9D4A4A27E47A0B2C9EAE21F6DDE61BC594D1FC1FE0C8D17A5 |
|
CONTENT
ssdeep
|
1536:FMERPBiyJIX/vnPWzeBQ2Y2E2n2A292z2C23WCmJ4o0wBor8WF18LY5hwiXAXJ:FZRuGTHsHw8fmQoIWrwN |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
edb616c949c912c7 |
|
VISUAL
aHash
|
ffe7efd9f1f10100 |
|
VISUAL
dHash
|
2b2f0f33331353d4 |
|
VISUAL
wHash
|
ffe7e7d1f1c10000 |
|
VISUAL
colorHash
|
0ee00000000 |
|
VISUAL
cropResistant
|
2b2f0f1333130353,0c08cbc9c908080c,a000a08d8d968084,49d4f5e1e8cce873,1b6cda9032ece402 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 873 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)