Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CA737031D08669730177A9C4AB686B5F22C1C38CCE574A89A2FE8B9C5FFBD50FD06158 |
|
CONTENT
ssdeep
|
1536:siLwEMxs8bx2FyjtqlCtSq/I/5Pih7cRiTfmn3X6aPL3pfPeiZJxIFZEuz0WxTVf:siLQ209Dnt5Ivpdjs |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
83fc924f386d124f |
|
VISUAL
aHash
|
00ffe7003c3c3c3c |
|
VISUAL
dHash
|
160c4c1260697169 |
|
VISUAL
wHash
|
00ffff003c3c3c3c |
|
VISUAL
colorHash
|
07000008006 |
|
VISUAL
cropResistant
|
8e9e06044d4d4d4c,cc8fb3b2b293b3a2,cc8eb2b29692b232,cc0e32b2b6a63696,1008121232520800,7012606969716169 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 184 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)