Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13C234B726332B47843DBA1DEF7382E05B2D2998AE9C74694F1C956CD23C3C802583BB4 |
|
CONTENT
ssdeep
|
768:as+EsZx8/G8ytF4UDaw6MLB6w6MLBqwZUcix+y9dQpUDF1E56ITmHDLBABW8KPqf:as+EsZ/8ytOUDaw6MLB6w6MLBqwZUXx8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d1eaca6a95919de0 |
|
VISUAL
aHash
|
ff40fa0e4200606e |
|
VISUAL
dHash
|
1a85cada8611cada |
|
VISUAL
wHash
|
ff60fa6e4200e0fa |
|
VISUAL
colorHash
|
31008010400 |
|
VISUAL
cropResistant
|
00000c0c0c080000,6668f0f0e0e081f1,714d233b6b196175,e4ccd4e0e0e0e0e0,60514d4f33396b27,1281cada8619cada |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 18 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)