Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18913E93104C86B2F91B382E49364764BE3D5814CEBB6C94DF5DEC31BAAC8D45C86BB58 |
|
CONTENT
ssdeep
|
768:/cGU3qoi+GbGv9gsdxgsJnew64nGMO/d1KUxqSHASLJSmUBo8q2EJiJ:/cv35i+GS9gsIOewxGMO/rrAKgo8q2ES |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9416ebeac9caca94 |
|
VISUAL
aHash
|
fd06060606fffffb |
|
VISUAL
dHash
|
71ccecccec1c1b13 |
|
VISUAL
wHash
|
fd060606060efff9 |
|
VISUAL
colorHash
|
0e000000180 |
|
VISUAL
cropResistant
|
0021892161890162,96d6e8b294710f8e,2c26abd9d968cf6c,e0181a2d13131313,ecccecccccececec,5b0fc6ceeec647c7 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 174 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)