Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F2B15831A884863312A3C9D09371AB3F62D6519DCE331B57E3F9475D8B8AEA7DC02645 |
|
CONTENT
ssdeep
|
48:d8JpQzcbkXSAlujwgLq80NUtFaJWLYqWGYVW1YDVW5Y3WWVY/WdY4WQYrWpYCZ4C:d3UpAj1oaJyNX8KyUUWasATNIUNKC |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c334476c1b3dd313 |
|
VISUAL
aHash
|
003c2c081c7c383c |
|
VISUAL
dHash
|
60e9d9d8b8e84949 |
|
VISUAL
wHash
|
007c2c3c5e7e3c7c |
|
VISUAL
colorHash
|
00000000c00 |
|
VISUAL
cropResistant
|
353663a3a58e3e3f,32b2d4d469785634,6c6c5a5a6a668c9c,94e054f0f4b2b4b2,9ebaa2b8c8be929a,60e9d9d8b8e84949 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)