Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19A13E61D438073AE151323DCAF32AB95B3AC50585B318A3441FBD61B7AD1F19D87EA9C |
|
CONTENT
ssdeep
|
768:0/44ORAj+ee2r6CIhINVcNZNNpa5YD6ZLU8e7eBY+W+T2Jby1I4gY:M449yw8YkDNpa5YD6Z2gY+W+T2J8gY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
be178501952f476e |
|
VISUAL
aHash
|
3fc78181818181ff |
|
VISUAL
dHash
|
f60f2d2b332b2737 |
|
VISUAL
wHash
|
9fff8181818181ff |
|
VISUAL
colorHash
|
0b000e08000 |
|
VISUAL
cropResistant
|
08098cc6e64e096c,772f693b332b372b,000180c2c2c00180,000180c2c2c00180,0106163616161609,a6aeccdcd85812c6,c5a4948116c9f9d9,a2a2d8805689c989,a2a2cc304689c989,4040434b4b434640 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 19 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)