Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13CE275A2C0C4797B0B52C6C4D7263BDAE2C28186CF579909EBF4476D7A8ACD6DC6205C |
|
CONTENT
ssdeep
|
384:KmEU7rMhAZIu+yeB9RK73wCWKGF1H1bdx9yCAFBHiS3bMDMdM3MjM51nMIxVth:kEEA93WKmcBrI2Iym1nRxVth |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9545d51f9e5a9382 |
|
VISUAL
aHash
|
7e62301c070fe0ff |
|
VISUAL
dHash
|
d8cae675ff58815f |
|
VISUAL
wHash
|
7e62000f078fd0ff |
|
VISUAL
colorHash
|
12400008040 |
|
VISUAL
cropResistant
|
6a4ab1a724e5646a,4e2d29734a57766b,2d262929aedcc92d,524c904d73cc0cb3,d3d3d036469e1679,52b2724a2a325d53,d41975e7bf0c5f58,cd87cda5e5a9b13e,8325845818dfc64c,d4d886caf414ef8c,5878001a00c98325,aeafc06165634363 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)