Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14C33F4A013C02A3BB40296E1B3719FE5E7E542E7CA4A39C293FE974D4F45D9688DE074 |
|
CONTENT
ssdeep
|
768:f1cn1bXK+eRK26PlqxV4uCHZpu02Va3m+nR2zwYnT:Cn1e+SK26PlqxVTWpu02Va3m+nR2UYnT |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d443c7b6434c9ce3 |
|
VISUAL
aHash
|
20000000ffffffff |
|
VISUAL
dHash
|
c888b8f0d02e2707 |
|
VISUAL
wHash
|
20000000feffffff |
|
VISUAL
colorHash
|
06000000032 |
|
VISUAL
cropResistant
|
e6b678681999bd2d,8989a1c131b1ed2d,c2c0c0c073c1e1e8,73e3d3c5e5517363,809a8ec888c888c8,d9dbe6c48d9ac889,5800000000000000,3c3c27264b0f2426,c8ccc8a898f4f0f0,d0d0dcd2d2d2dcd0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 903 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)