Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11F0253E1D064DD36071281D6FBF57B6F7AA2C345CF02098453F853AA6BCEDA0CB12599 |
|
CONTENT
ssdeep
|
96:TkRGzjwLTSTRR8v67edtaNwvFfQehX0HFnedXlX/iVz7vSTu1+GAT43a:QRGzjwLe/8iKd4aeoDXaz7661M8K |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ba4a05a545430fff |
|
VISUAL
aHash
|
204dcccdcf8f8f8f |
|
VISUAL
dHash
|
c3991999193e1f1a |
|
VISUAL
wHash
|
004dcccccf8f8f0f |
|
VISUAL
colorHash
|
07200000180 |
|
VISUAL
cropResistant
|
c3991999193e1f1a,80053c40c2000016,5d6d1584956d5d55,02a0021213136380,3e2773c515180133,2f2c6c27b7b76ef0,c994183858d08a8c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)