Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12F62FE25918558C7C233A5C8E4952F1F60B7F31E8289CB47EBA0905EEF8FE012E76945 |
|
CONTENT
ssdeep
|
384:PxqcrFTR9bsfb2foN44x4blLFxE3pdIHkkZM3TAAR2+b5O2:Z9uOaK2 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d82b00deef811c9f |
|
VISUAL
aHash
|
180008e9fede5e5c |
|
VISUAL
dHash
|
f1d7d1d32c20b494 |
|
VISUAL
wHash
|
18000cfbbede5e5c |
|
VISUAL
colorHash
|
02401040000 |
|
VISUAL
cropResistant
|
7131b2f0f0f0f0f0,f0e4f071d8ccccf1,4defaf8be2c8aca5,b4ac8683e160ece8,629c2c22a0c68690,f1d7d1d32c20b494 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 46 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)