Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15E81863574C828271BABD3197D91972D539389AADB130F5296E0190FDED2E06CC811EF |
|
CONTENT
ssdeep
|
48:YAVVd6jPJYoD/k6jPBrRV9FP1A2AFP5fJtWtFPO0HUNCn5ilX/fmTJCnyUR/WvxQ:z09TBn9YLfqtUmarP23Nu |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d7dd04f632191b32 |
|
VISUAL
aHash
|
00ffffffffff0000 |
|
VISUAL
dHash
|
0c0028300c0800c4 |
|
VISUAL
wHash
|
00fffefee4fc0000 |
|
VISUAL
colorHash
|
0e0000001c0 |
|
VISUAL
cropResistant
|
00102830080c3000,0088404d4d408800,0000203232000000,02c4c4d4ccecc402 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 51 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)