Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B1654CB0F55C11BD40CF56C890125EEC775BA0AAF46304285AFC96ACEAE2E65C50FC7E |
|
CONTENT
ssdeep
|
3072:7BZNeLTpSnScVi1DVCqyTYUegDxc9UqPP4SyI5oZSmTLPiEu6lCAk6eoR+lmwoQj:74CS9ypwykAPiEu6lCAk6eVoQxlDX |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cdcfe38669413466 |
|
VISUAL
aHash
|
78ff0838100c7c00 |
|
VISUAL
dHash
|
e3f0f2b230fcc033 |
|
VISUAL
wHash
|
78ff3a7a180e7e00 |
|
VISUAL
colorHash
|
12202008080 |
|
VISUAL
cropResistant
|
8200828282828082,c0101700f0f0f0f4,7dd49a7d7cba3212,d9d5553555555092,fd5c4b49441228a1,0f7ae62cce0c8007,42421cd2e2e2f28c,f4d2f232ecf8c232 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 296 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)