Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D09334219725793B40BAD9C16A26476F73F3E50EC9830652A3FCC35C6BC9D88ED21939 |
|
CONTENT
ssdeep
|
384:C6eIqUw2DwyigmzQ5UemaPM6D7oCa/uaE6U4qdhGYMdYoLJOBYGS+ALfQKWKzB1w:BeIuJgmzj0d7oCR/6U6GcpOId6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
eb6b9594663691c1 |
|
VISUAL
aHash
|
ffe1e181e1ffffff |
|
VISUAL
dHash
|
4703030b4330170e |
|
VISUAL
wHash
|
e181e181c1dfc3e7 |
|
VISUAL
colorHash
|
07601000040 |
|
VISUAL
cropResistant
|
4703030b4330170e,c6f6f4f0b9653f7f,236366464ca61e2e,4d457844460c9c92 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 71 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)