Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10F02799CE26598335561C1E0E86A7BDA31408E4AD7832B1557FCC136FEC99EEED023B4 |
|
CONTENT
ssdeep
|
96:TkWTGW8r9B2iaBDjU3F9X2vKyJOiU+9P6z1sGJ1ErnFAEU8Sg3dHXi5qo0XRFIBc:xGnRoiaoXyJ6zKVDmEUI3d7oQReBZ61Z |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cbdd3c32dc28d12c |
|
VISUAL
aHash
|
383c3c3c3c2c0101 |
|
VISUAL
dHash
|
f1e9e9e1c8c9135b |
|
VISUAL
wHash
|
3c7c7c7c3c3d010b |
|
VISUAL
colorHash
|
320000001c0 |
|
VISUAL
cropResistant
|
b4b7ce868ee3939b,e4ac075b5b251dc6,f1e9e9e1c8c9135b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)