Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DB73E78A5454202A472740E348BB2FC9B7785C3FF92942D1A5B8C7E5B3DC8F53266B4B |
|
CONTENT
ssdeep
|
768:jyWuPuy15SsH/cNwG9XM1n/qZW8+WFTH+L/utDnX8Uhh6c6Brz3MnCu/fn9S/Wq8:0yOloQzZs8oWQbp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
818cf24de396332f |
|
VISUAL
aHash
|
7e1f1f1f09000eef |
|
VISUAL
dHash
|
f8f1fdddd3ca3c59 |
|
VISUAL
wHash
|
3c1f1f1f01020fef |
|
VISUAL
colorHash
|
07600010200 |
|
VISUAL
cropResistant
|
fcf1fdfdfdd3cbde,a202c44b53512292,18a649494958181c,f8f0f5fdd7d3cabc,45452b98c42b5501,f67c1f87c1b0a0c9,a74b8b9329294949 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 694 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)