Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T115249F786928AC2E4641848DE1CF3798715FC24B8B0243AB735A2E7F87E14B7757C663 |
|
CONTENT
ssdeep
|
1536:6n14FH5y4oHYP2kui9Tr+4+f+4HIHxD1Hiuni9kPFIrod14ZGF:VUYmwjb |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f08ad28b74a9de70 |
|
VISUAL
aHash
|
ffe7c3c3c3ffc2c0 |
|
VISUAL
dHash
|
59482a9696695c54 |
|
VISUAL
wHash
|
ff21c3c3c0fcc0c0 |
|
VISUAL
colorHash
|
01007000000 |
|
VISUAL
cropResistant
|
59482a9696695c54,69e48d6b8b8ad232,0555a9a93763b9ac,44946c69b2967175,12326226995bc9c9,d9999ae56515d5d5,3979f8a8ade9a3b1,33ccac4cce9c8c63 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 675 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)