Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C88325F0424400BE46D2B984E9A2FE1791F3CCF6EA0F1C9996BC594C5EC1FA0D9E52E5 |
|
CONTENT
ssdeep
|
1536:V+nkxeRix/2WEv8epPvpeyCA9LjvHoUdUXrkA9otJZkLv1hcov8DSFeH7p0P6bgU:V+nfR51MRCeoB |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed5a424d2f1a632d |
|
VISUAL
aHash
|
00fe8e9b93f3fba1 |
|
VISUAL
dHash
|
6949383232c2636b |
|
VISUAL
wHash
|
00fc8c9a93f3f3a1 |
|
VISUAL
colorHash
|
07600008000 |
|
VISUAL
cropResistant
|
6918383232c2636b,0004141414040000,5b5f7d5b7d4d4d7d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 261 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)