Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12714B660E63C542F400B61D9E59CAAB3BA44E964EFD08040E9EC83CFE956E51F77B16C |
|
CONTENT
ssdeep
|
3072:c21ntn+nHZntn+nHbuChG+a4SWM0+yx3U60/TmlJR4:csuChG+a4SWMEWmlJR4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e0401fe271b1dd3b |
|
VISUAL
aHash
|
0000426762ffff00 |
|
VISUAL
dHash
|
a1a3968e8e867f4c |
|
VISUAL
wHash
|
00107e6766ffff00 |
|
VISUAL
colorHash
|
06e01000040 |
|
VISUAL
cropResistant
|
ec708b1b6be7f1b3,4f8e0eccccc8e0c5,fefdfffde8988103,b2968e8e86f97f48,c8c83d07c3c8d8d8,d2a1a3b2868e8e8e,232b2b06062f2723,3f634c1c81e8aee8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 251 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)