Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16E91D97490219D275182D2D8B5B55B1F33C2D388CB434B0967FC979D6BEAEAEDC14058 |
|
CONTENT
ssdeep
|
48:T7YpcrUCFNhP463eIEZ3dGI7xwoHuImqawv82GT8RIERB6ZmFwqKfNCjTQfxa:TuHCF1eNRwoHp/J8hT8sQFwquUPow |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d2a42bcbabd65494 |
|
VISUAL
aHash
|
fffc1cfffff8fc01 |
|
VISUAL
dHash
|
c3f8b4e71ba0585f |
|
VISUAL
wHash
|
f8e81cf7fdf80800 |
|
VISUAL
colorHash
|
07001000180 |
|
VISUAL
cropResistant
|
c3d8bce51b80585f,c4dae12555f1b3d4,b5a5e50311010101,3093539393503131 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)