Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CA343030A2839D37B1A7C0D0A360EF5B7395839AD6174F0A57F853DEABCAD81EC14949 |
|
CONTENT
ssdeep
|
768:AG5SSu6spdP0pWckiCP7n+pyavN1ictk9rN5pK97Xh:264P0pWckiE7n+xN1ict6K97x |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b91ac7c7c33838a6 |
|
VISUAL
aHash
|
36008381c3c3d3ff |
|
VISUAL
dHash
|
454c3b3b1b13230a |
|
VISUAL
wHash
|
3f008381c3c3d3ff |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
205a546554558c4c,3b3b3b3b17332a1a,000100030b0b0002,23c4c4c434140300,ebcdddb99bbdcdcd,cdcc0f11941e9a96,0024697161691620,9c336143b3674e1f,c9a0e151476f4f1f,c285c7c6af2f5f1f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 189 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)