Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T129B254308210AD1BA1E3E1A4A6F18B1B7241C381D3475B6D57F49367EACECD1CE752E9 |
|
CONTENT
ssdeep
|
384:zLf/vGLNgXYe3m/dERFmXBFfHLDXAPbeo1XGcv:zj3XYe3m/dERFmXBFfnSJ1XGcv |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
999b6664999b6664 |
|
VISUAL
aHash
|
0000003c3c000000 |
|
VISUAL
dHash
|
00000c78700c1010 |
|
VISUAL
wHash
|
0000043c3c383830 |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
00000c78700c1010 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)