Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14571D721A1C2180E17270168BD8AFB0F4F2F8B8D970646280AE536EED2CCD755DB675D |
|
CONTENT
ssdeep
|
48:oXKIdyEwBiTLfQnKTdTQn/C49iTLfQnKU028czZMb5ne/yNkICSmL1qBgy4In7K:yddfjswfJQWn0KCN1qBgy46u |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a87068595939f5e6 |
|
VISUAL
aHash
|
0000ffffffff83ff |
|
VISUAL
dHash
|
82a68632f2475725 |
|
VISUAL
wHash
|
0000e3ffffff8101 |
|
VISUAL
colorHash
|
0e1c0000000 |
|
VISUAL
cropResistant
|
868633f3c8577725,008292929200a080,8d5555557576361a,5b5ba7c787a5b51b,656564562a6e6746,aaaaee43a9293517,9a9953434a475404,e9695414b4d6ce4d,e2e2ea4a5a5a9ca4,25456d6b74948a2b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)