Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C534A73D2300E73E3287C56DDA65B6E2A38E7C65D95FC5A6C3FC564BDE9A890C502E00 |
|
CONTENT
ssdeep
|
1536:eQA6N7c54z3su23QZd3yafJVEgKscoEbPv4At2Sr4wn3ZWS44fNWSynBp4WS6suw:1AqiyHwDN4C7kU8wR |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b805bbc5f0c6d0dc |
|
VISUAL
aHash
|
ff0818080000ffcf |
|
VISUAL
dHash
|
bc3ab175b6963b3b |
|
VISUAL
wHash
|
ff0f1c080002ffdf |
|
VISUAL
colorHash
|
16e00008000 |
|
VISUAL
cropResistant
|
be00208c8c3200be,636ac6d6e4bcf97a,8be038fb79f0b2ea,ce4aca3959ca4ace,c43f333b3b3b3b3b,80b0b0b0b0a4e2a2,bc3e3ab19174b696,67e9f8f8b8b83878 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)