Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F9C464B5DBA8CA7E0A3782C5A6865F5673F98154F8EB011243FE87F51AE7C44F803069 |
|
CONTENT
ssdeep
|
1536:81IIbWF1GeU9iH+k7cE9f4MjQavNlHsymAXzTjOTXgRcLaI/WCyzUE21d2pi5Ym2:8vC1QVW5zUrqq+tmrCIOTrXP |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ef4c418744ac1eeb |
|
VISUAL
aHash
|
3081c393c1f7ef00 |
|
VISUAL
dHash
|
e41b33270b2f0b4b |
|
VISUAL
wHash
|
3081c1d3e1ffff00 |
|
VISUAL
colorHash
|
0b2000001c0 |
|
VISUAL
cropResistant
|
a18082e2e28280a1,1b23232f0b2f2f0b,8e8c964c94aa8e2e,9f4f475355654515,4c59e6e6a19ad284,9a6a6223629a4d40,85a5a5b1cddceece,2f2f0b0b0b6b404b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 94 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)