Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13E53EAD628956016077290D3A4BF3B4AB379182FB92C15E1B1B4CBE571F88E5206BF4F |
|
CONTENT
ssdeep
|
768:MyWuPyuW5u5L//C8onGQRzLcoN9BzFvXUsz8n+IDS/u11KWU+dFfISZ5CTH+M6XZ:XSyOloQzZs8oWQbp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
916e6e99e995a9c0 |
|
VISUAL
aHash
|
f1000f0f0f0f0e00 |
|
VISUAL
dHash
|
03bc9a9a9a9adacb |
|
VISUAL
wHash
|
f9000f4f4f4f0e27 |
|
VISUAL
colorHash
|
3ac00600000 |
|
VISUAL
cropResistant
|
7438383c3cbc9dac,fef9e9c1a2c6ccc1,03bc9a9a9a9adacb |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 700 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)