Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CFD1BCF2A9D2D93341F7D0D16AB66B1A33E4825CEA830A4157FCC3D90BDEC52F85A600 |
|
CONTENT
ssdeep
|
96:KmMIdmY/iGaIiZi2Sxia875R7iGghWMxs9Mz1Gbb2r6coyzcpcH/FkbGzXRgMOL5:XrmYHgsxMLybxs26XIiMqMkvnZ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b66969365a36cdc0 |
|
VISUAL
aHash
|
00013b8736370778 |
|
VISUAL
dHash
|
1febf76c6c6ccc94 |
|
VISUAL
wHash
|
00037f87f7370778 |
|
VISUAL
colorHash
|
19200038000 |
|
VISUAL
cropResistant
|
94829885a64c9d9f,ed6c92b332324ccd,6d4caa6b6d68d353,f490a2a616f6ecc8,b2b349494949b2b2,dadbd3d3d3d3dada,cec2c7b12c2576f2,093b24ecaa8a242b,1febf76c6c6ccc94,51616971138eccf8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)