Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10391843B58089C0C1F72C638BED5F219CA52EDC6E59E5589F5CC924E2BC0E75B183349 |
|
CONTENT
ssdeep
|
96:Hr8WyW9WHWeWAWLuUvny74zmZHEFnYbOl:Hr8Poi17jYy4zmNEFnYbOl |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c487d52a7e0eb81b |
|
VISUAL
aHash
|
7efeff77200000c0 |
|
VISUAL
dHash
|
ae8e8ee4e5a5aab6 |
|
VISUAL
wHash
|
7efeff76304000c2 |
|
VISUAL
colorHash
|
06600040008 |
|
VISUAL
cropResistant
|
a68e8e8ecc65c1a5,cbc560b2c1607cb8,e5653cfc6a64e4ec,1c1c383870f0c187,8aa0c0f1b9bc7cdc,9eb4b03030909212,9f7ec650a6a6a6f6,ae8e8ee4e5a5aab6,3c7d495959797979,0703939312121213 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 11 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)