Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19DA3DD238159352B4437C3C134695B3BD1A6D98FFEE70A404EDCCBF62AFAC90746A259 |
|
CONTENT
ssdeep
|
768:YGhzA+tpR4nXF6YjOpSpFlTC6rrW0oCrMrxNQFTpOtDMt1mqf7:ztpR4nXBKpSpFl26v0qEvQFTeDMtAqf7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
926d6d13136c6d65 |
|
VISUAL
aHash
|
001f013f7e0f0d03 |
|
VISUAL
dHash
|
dcb927dcdcdcbbe7 |
|
VISUAL
wHash
|
000f033f7f1f1f07 |
|
VISUAL
colorHash
|
00003400400 |
|
VISUAL
cropResistant
|
f96bfd9898797bcf,dcb927dcdcdcbbe7,d51d8a4d4db259da,0e4721130e1c3424,94210c3232080121 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 113 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)