Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FD336270B448993F2157D1C5F227AF0F70C0C38AC6975B89EAF993BA9AD1C70BC66644 |
|
CONTENT
ssdeep
|
384:EP7lJ6JOgGkr1SaI36wEfERNnwQrtCQKe8j8S89Ww8v8PwwgZ5svm9pzhvzOABBw:y+OgGkrI8fuzEVYP9WNkYt5BSb7rt |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
96b4c569e9c33c46 |
|
VISUAL
aHash
|
ff0606ff000020ff |
|
VISUAL
dHash
|
7b4c4c0c1333c9c0 |
|
VISUAL
wHash
|
ff0706ff810020ff |
|
VISUAL
colorHash
|
02000001180 |
|
VISUAL
cropResistant
|
7b4c4c0c1333c9c0,355455351d5d1521,716979732f7f7b3f,05d1d96565182105,0810b2b232c8c8c8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 942 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)