Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10473E932D3451103D08798D8F1269B4B7352879ACA138FB477E81779EACECF52B62399 |
|
CONTENT
ssdeep
|
1536:od75E85Nps8fFQnMr9dVtRRp5IHLonjpv/pQ/40srxk222I2222222St8tVtFtCd:+jNbzxjp/oOxk222I222222260brKMcJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c126cf329293e7ac |
|
VISUAL
aHash
|
60007a4e42607e7e |
|
VISUAL
dHash
|
caa2e2988a8af2fa |
|
VISUAL
wHash
|
f2407a4e52427e7e |
|
VISUAL
colorHash
|
03200038000 |
|
VISUAL
cropResistant
|
caa2e2988a8af2fa,04c836fc15152d2b,044b36c8c834a393,c9cc31831bbb359b,04cb36c8c834a393,4b4b3198d8d08c4d,c8cc30431bbb37d9,3e92db4bd31a2b2b,676d4f7747597b23,04cb36c8c824a393,d9cd30431abb279a,9597e328d0e09080 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)