Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1167176709040DC3F2243D6D8F3EAE71F37D9C2A4CA96050266F887BD5EDAD42EE61619 |
|
CONTENT
ssdeep
|
96:DusuXwCZwlk97opATNL6UM6BGIDYkxZYYk6:GXwCZGCkOzDDY+ZYYp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
94d67a700fc6e06d |
|
VISUAL
aHash
|
246e7e3e3e4e0400 |
|
VISUAL
dHash
|
eccce4ecf29ccc32 |
|
VISUAL
wHash
|
647e7e7e3e4e2400 |
|
VISUAL
colorHash
|
190020000c0 |
|
VISUAL
cropResistant
|
f0f8f2f09e9c94e8,39e0e0f0e2c0f8f8,6e6c7c53b6fce8e8,f9f9e1e1e0a68ecc,8280a2d2d2a280a2,a280a6e068e080a2,eccce4ecf29ccc32 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)