Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T149E33AE7D078993F037AC3C5A6907BDA74C7638EC59000A5E6F89E7D83DAC517A4AC18 |
|
CONTENT
ssdeep
|
1536:p0GzFRcKTrZj+iKKcglx7GGZDx9UV7LeztbFyLJu7GSbQBzeLBHgnDu+wBvG0bGX:qkcKTrwOA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f38c58bce03b3863 |
|
VISUAL
aHash
|
fe3e28e266c6c4e8 |
|
VISUAL
dHash
|
e4646aeacc1a5999 |
|
VISUAL
wHash
|
fe3e6aea66c680c0 |
|
VISUAL
colorHash
|
13180008000 |
|
VISUAL
cropResistant
|
e26aaaeac68d4c89,5cb868dcb2a34d1c,63d7ceecd26a6ab0,e4646aeacc1a5999,b294d5555555d4ac,7176b46546864ece,d4546a66526a16d6,6565b59191b52433,4183302121053d7c,49b5a79bb7abaab6 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 756 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)