Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A192D7F2B656143B9E73C3C0A6D57704F646400ACAA096D09BFC85ACA2D5FB2E193377 |
|
CONTENT
ssdeep
|
384:LuTn+CjhgdFlsO6MeYTMnIEip7QXc9AMHO8:4jhgN69znR07Mc9AMHO8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d6c8583233b3d31b |
|
VISUAL
aHash
|
c8f8ffffb4000000 |
|
VISUAL
dHash
|
9831e0cc282c2c68 |
|
VISUAL
wHash
|
ecf8fffff6000000 |
|
VISUAL
colorHash
|
07206000040 |
|
VISUAL
cropResistant
|
8810b1e0cc4e28ac,66c4c3d8d9d8dac6,838381130206040c,0800206342660400,662cac6daca9286c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 18 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)