Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A5F262B1E084A43B1463D2D8F3746B2BE7D1D718CE930691E6F4834E4BCBE62DE51268 |
|
CONTENT
ssdeep
|
768:HXLhd3c3o14u+OdDsjZX5QlHGoksRQfiCzV:HXLhd3c3o14u+OdD2OGoksRQfiCzV |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ac87563b11792dc6 |
|
VISUAL
aHash
|
087773631b81c040 |
|
VISUAL
dHash
|
33e4c682a33332b6 |
|
VISUAL
wHash
|
1cff77631b83c042 |
|
VISUAL
colorHash
|
10000038200 |
|
VISUAL
cropResistant
|
8cacac8590909dd9,86cefc7079337c1c,6c6cddcc24626c72,6749b26490e14286,33e4c682a33332b6 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 124 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)