Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B6837632E3971903906BD2D8B171471D22918789C7134B7567FD27BAFACECB63622398 |
|
CONTENT
ssdeep
|
1536:wVQe4iZPlMeeee8ceraw5epevepeKepexe7H7ZeeoepeseJehe0DxV+Ng6QQNMz1:obt8VqDGyJUbJeRhJAJDJzEoAmTnmJRh |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e12e6b391e93c986 |
|
VISUAL
aHash
|
60707e46526a6868 |
|
VISUAL
dHash
|
8aa6e494a4d2dbdb |
|
VISUAL
wHash
|
6230ffc212ebec68 |
|
VISUAL
colorHash
|
01000038000 |
|
VISUAL
cropResistant
|
8aa6e494a4d2dbdb,8280175763397141,0909656a5bc9cac5,34262646662d3c2e,e631126a6dc5cdcd,3509c101410f1134,2109c101410f1034,ce4b5878696b3121,d7693248cccc446c,7911314c481d94c4,9686d0ccc69282e3,8796c56bb271f0e1,3509c14101410b34 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)