Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T109F2543391959C028052D1D8F271D70E7342C3C6CB4B4B5663E88BAE7ED9CF6AD22399 |
|
CONTENT
ssdeep
|
768:mZFXlxYhsib9Y2mI4zCdbYx1qS62tZN6j2TmTTE3m8ZCOSUv1DrHmh+TCkDwmMRQ:ihBewvZN6LHF2nJCkDwvQ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fa2e3291b469b4ca |
|
VISUAL
aHash
|
83818181ffededcd |
|
VISUAL
dHash
|
37252323999999a9 |
|
VISUAL
wHash
|
81818181ffededc5 |
|
VISUAL
colorHash
|
06000030000 |
|
VISUAL
cropResistant
|
37252323999999a9,caac5d96a4e4e4d8,a89a3338807c6a6a,659ab6b6b6ae8e51,b2a484c4b486d654,3f47e4444369e31a,2e8ca2aa682aa2e4,28ba3a3834646121,f0afb7feb7b1d4f8,0414716b73e2aa9a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 31 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)