Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T164023472C0CA655F134BC1C2E1B7F5999842F50EDAAA4E55EAD44BC9F381EA0FC721C4 |
|
CONTENT
ssdeep
|
192:unpGyAnYN5oi70pMORanmIL2D2s2D2D2D2E2D2w32D2E2D2q2D2U2D2E2D2g2D2w:0AYN5oi70pvR6L2D2s2D2D2D2E2D2w3P |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
855e6aa17f8c3869 |
|
VISUAL
aHash
|
0000183e6e7f7f00 |
|
VISUAL
dHash
|
717170e4ced6d2d3 |
|
VISUAL
wHash
|
0018183e7f7f7f28 |
|
VISUAL
colorHash
|
30400038000 |
|
VISUAL
cropResistant
|
fdbd2e7cf1c2c28d,3b1b96a4a8b1f372,dec7c6c6cc989c9c,d0cfcece8cd81c9c,c6cece8e8cf42c1c,a82ad29d95157567,717170e4ced6d2d3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)