Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C002DC20101ADD3394D396E5E2B5972BF1C6C30ACF1B1B06A3F997EE1BC6C84ED12664 |
|
CONTENT
ssdeep
|
96:D0S2u1bG0CEcE4883W2VFZfsYgsmQ1RsVOs/tswA7Js4oOsYXP6ShU6gS2195ZW1:D0S31bvw35m6UZSd |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9c9861e76a6ac363 |
|
VISUAL
aHash
|
0f1f1f1fffff0000 |
|
VISUAL
dHash
|
ba3654397a341aa1 |
|
VISUAL
wHash
|
0b1f1f1dbfff0000 |
|
VISUAL
colorHash
|
11000030000 |
|
VISUAL
cropResistant
|
82f9b6ba383d3676,78e1869b93931989,cce0320c9d85cad2,9c95c7ca31399b86,74b97cfcf4f8f9b4,753aa57acc3d3619,0000000000020303,b6ba36525432ad73,6c181b80c3473e38,3c696372b49387ce,8cace9e96a271d0d,966618198b540000,d2d23a9b034a4808 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)