Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D8336390324149F910A383F1B3D2F799D1BCC788DE2B9D7AE3D903532789C5DAA527A4 |
|
CONTENT
ssdeep
|
1536:ztqESQTf8LYY6kW0bBmoZxuOp8LK9CNBnO+7m5u9TfGZ:1ho |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a7bf1961e0492937 |
|
VISUAL
aHash
|
fbff83e3e7000000 |
|
VISUAL
dHash
|
926c2f470dce6079 |
|
VISUAL
wHash
|
c7ffefe3e7000000 |
|
VISUAL
colorHash
|
33200030000 |
|
VISUAL
cropResistant
|
536c2f0f674d0c0e,dffee0e8a8f0c08c,0241aaaa8aaa4000,6c0f674d8e476179,0f7262646262b20c,717171717131310f,b4b4b4b4b4b0b541 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)