Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17BA36032A27B1512A01FB1E4F2648B452753CB97CB034FF651BD16F5EA8D8B82E6318D |
|
CONTENT
ssdeep
|
1536:7ypYe6LlESRfOwF7dV5kcXyFXvQ/ovup7MPW7LCy3Z6+HKJGUqTNGefereeeUOp4:9KSR7UBUNq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c126cf30b19bc6ad |
|
VISUAL
aHash
|
68007e6c40407c7c |
|
VISUAL
dHash
|
cba6e0988a88f2f0 |
|
VISUAL
wHash
|
f040fe5ec2427a7c |
|
VISUAL
colorHash
|
03200038000 |
|
VISUAL
cropResistant
|
cba6e0988a88f2f0,49d964f031272b2b,a619f60d2d039a03,a619f60d2d039a43,4b4b7198d8d08c4d,a5267464c3c77633,3e96db4bd3122b2b,e619f60d2d0b9a61,4f6b79692b3323c4,a619f60d2d0b9a61,9597e36890e09080 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)