Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FA13B875D35029331A33C2EEB4B51F19A34196CAD3D30B8992EC6F3E7D89E60790658B |
|
CONTENT
ssdeep
|
768:i61gSrwIV+NgmUveNkOJ564XIUjgToM2jNoIdLGkxjiMlIq/pq8qm92aRxVkDuKP:rW/gmUveNtJ564XIUjgUhddLGkwMlIqu |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b9662827b3b1c6b2 |
|
VISUAL
aHash
|
0000ffefffffcfdf |
|
VISUAL
dHash
|
96b6949898999191 |
|
VISUAL
wHash
|
000010cfcfdfcfcf |
|
VISUAL
colorHash
|
07006000080 |
|
VISUAL
cropResistant
|
96b6949898999191,3333331ab7ab9ab2,4353a5a1d9c96753 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 68 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)