Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T153154CF0E31C11FC850F47E98635697C336F30F7B912447889ACAA785563AA4CE5BCA9 |
|
CONTENT
ssdeep
|
3072:/ZNeLTpSnScVi1DVCqyTYUegDxc9UqbhsyiPFLHRDISarmJX:qCS9yp2hs3HDISvJX |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
891f54477668bd07 |
|
VISUAL
aHash
|
00ff191d3d7960f8 |
|
VISUAL
dHash
|
e2f333915bd3d780 |
|
VISUAL
wHash
|
00ff191d2f2960fe |
|
VISUAL
colorHash
|
02001000180 |
|
VISUAL
cropResistant
|
8282828282820082,3b7391995b53d3d7,4247b59bb5b59526,2d162e2a3636b6c7,32b4e4f6d48c9181,4507a694d4d6d450,7767b431adb591c3,a581c3819c3e0110,c4c49c93f2f29398,3b93995b53d3c780 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 42 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)