Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14032CAB06056BA7791D7E6D2A7B9672FB2E18287CA5B130423F99BD80FC7C48EC05147 |
|
CONTENT
ssdeep
|
192:d92s1io/XsD2XqaqXS7aXKuE2uLOnZWDAqU7VZEf89dlK46KC+:d9Rb/cD2hqCwg09dlK46KC+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fc43b883299ad27c |
|
VISUAL
aHash
|
ff00000000ffffdb |
|
VISUAL
dHash
|
2b43745442cc2b33 |
|
VISUAL
wHash
|
ff00040000ffffdf |
|
VISUAL
colorHash
|
02002c00000 |
|
VISUAL
cropResistant
|
2b2b040303686022,80808288a880aa80,836c6c9333950101,8080a0a088e0a088,8080a0a080c08080,bedeb6b6aee2fa9e,000834b4a6e86906,0032cc2b33333333,0369207474404000,02000000808000c0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 31 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)