Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1878528A0D24C91BC445F13E582656FAD335F20DAF452053CAAECD66CA6D2EE4CE0BC6D |
|
CONTENT
ssdeep
|
6144:9UCS9yp2hs8pxFRhRLWV06gyWvXoJS0i0M9nPQQQ2nhDX:9vpoxnnP/DX |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cdcfe38669413466 |
|
VISUAL
aHash
|
78ff0838100c7c00 |
|
VISUAL
dHash
|
e3f0f2b230fcc033 |
|
VISUAL
wHash
|
78ff3a7a180e7e00 |
|
VISUAL
colorHash
|
12202008080 |
|
VISUAL
cropResistant
|
8200828282828082,c0101700f0f0f0f4,7dd49a7d7cba3212,d9d5553555555092,fd5c4b49441228a1,0f7ae62cce0c8007,42421cd2e2e2f28c,f4d2f232ecf8c232 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 167 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)