Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16A2365F290A4D077078EF6E0B566671FB7C3878BD9460FE29AE847185E86DC18E1341A |
|
CONTENT
ssdeep
|
768:01gMkvdq3FGMq6COFXQdC3gf6IgMkvdq3FGMq6COd2/RPdXwlfK98c2705C81O7z:01gMkvdq3FGMq6COFXQdC3gfNgMkvdqz |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
953e6f634c1511dc |
|
VISUAL
aHash
|
00005e7e7e6e7e7e |
|
VISUAL
dHash
|
41ecb4b2d2cac6f2 |
|
VISUAL
wHash
|
00005e5e7e6e7e7a |
|
VISUAL
colorHash
|
0e007000000 |
|
VISUAL
cropResistant
|
3222b2b2dacad2f2,41ecb4b2d2cac6f2,6153676749690939,8bd9391f2163c666 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 61 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)