Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16473653080019D2B06D3B2E0BA316BA9B6D24349CF174A4992F48F9DFBDEDE1CD295D4 |
|
CONTENT
ssdeep
|
384:oR/Vtkr54Fv+uWyTt0ub2BncPGmkv/3Y5JjglT3Y5tivjniMXzzrLLEk0jr4YbCN:oVqOFG00+8/aqnvjniMhCrfbCmoQfrG |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d906f03d4730cf1b |
|
VISUAL
aHash
|
00003c0098d9dfff |
|
VISUAL
dHash
|
94a3e8d453331310 |
|
VISUAL
wHash
|
0000383c99dbdfff |
|
VISUAL
colorHash
|
31001600010 |
|
VISUAL
cropResistant
|
9c175753517bbbbb,494999db656b8cb5,245c5965652bab62,5626269696060616,932edc3860c08000,9c82b0a92dd4f4f9,94a3e8d453331310 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 23 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)