Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16B92A4B241249CB31A23EDD89F89A704F346810ACF5229A9D3F4C78DABDFD94F54294D |
|
CONTENT
ssdeep
|
384:TwLLyCyrgK2q2OGY8m2cDCeZ4DWHWH2Kp+Qse7JbG:QyCyrg9cDCeZ4DW2H2KNseli |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f10f0ff04f237c81 |
|
VISUAL
aHash
|
002020e0e8c8e8a8 |
|
VISUAL
dHash
|
44c8484098989848 |
|
VISUAL
wHash
|
207c2cf8ecc8ecec |
|
VISUAL
colorHash
|
38007000000 |
|
VISUAL
cropResistant
|
c666d9c8f966c6c0,44c8484098989848,391ea7211fbcbb5d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 736 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)