Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1949474F59148B2F1130B8FC4D9335FAA795B597AEE4F618C92E98290D7E2CD4CC48D88 |
|
CONTENT
ssdeep
|
3072:CALnJEoKyYTxJv/8k5HlrHGgzuygUjRs5GNd+HtxRJedz733TJEoKyfRUvkQvfXb:HQE |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9ff978a766608584 |
|
VISUAL
aHash
|
889c1c003e3e0038 |
|
VISUAL
dHash
|
3a38f86a646c5e60 |
|
VISUAL
wHash
|
8abe1c163e3e0a3e |
|
VISUAL
colorHash
|
38400018000 |
|
VISUAL
cropResistant
|
e4f0f0e0d11e3c8a,78eca659d8e8e0e8,adccac2d4ccc6c4a,b6b6b33330323195,f423138e6c61e0f0,3a38f86a646c5e60 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 167 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)