Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A8837672E3971813906BD2C9B171471D23918B89C7134B7563BD27BAF9CECB63622398 |
|
CONTENT
ssdeep
|
1536:UWQe4izDTMeeeeMceraw5epevepeKepe3e7H7ZeeoepeseJeheLxbNgcQQJMjWfR:pbM5Xd8JUXJNJAJ8Jzs0AmTnmJz+bVlJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e12e6b391e93c986 |
|
VISUAL
aHash
|
60707e46526a6868 |
|
VISUAL
dHash
|
8aa6e494a4d2dbdb |
|
VISUAL
wHash
|
6230ffc212ebec68 |
|
VISUAL
colorHash
|
01000038000 |
|
VISUAL
cropResistant
|
8aa6e494a4d2dbdb,8280175763397141,0909656a5bc9cac5,34262646662d3c2e,e631126a6dc5cdcd,3509c101410f1134,2109c101410f1034,ce4b5878696b3121,d7693248cccc446c,7911314c481d94c4,9686d0ccc69282e3,8796c56bb271f0e1,3509c14101410b34 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)