Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10B42CDB8A2187D9F4642824CB70BFB51711BE1CDC72283646047DF3EE684DB7B626672 |
|
CONTENT
ssdeep
|
192:rnV8lw9/T3e7IcKJtvQfmY/nviAuV0F+vASdt3Um4Wvsf8FYGI3qkz/bOI9FArif:rnV8lI/TO7IcKJtvQfmY/nviAuV0F+v2 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d919368ccc6674f8 |
|
VISUAL
aHash
|
0008c8f8f8f8e0e0 |
|
VISUAL
dHash
|
001a1212b2b24008 |
|
VISUAL
wHash
|
80f8f8f8f8f8e0e0 |
|
VISUAL
colorHash
|
31e01000000 |
|
VISUAL
cropResistant
|
e08060e2e0909084,f082028204040509,84a3980402010000,e0eba3a0a18031b1,0000010200040109,c288b1e1c8d4c971,001a1212b2b24008 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 12 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)