Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T196B300235256292B0477C2C03065AB3BD1E6D94FFEE74A015EECC7B72BF9C90B44A658 |
|
CONTENT
ssdeep
|
1536:YHSrpR4nXBKpSpFl26vKoxqdDL3G7LN44u:YHS1UMno4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bcbc1347e413bc64 |
|
VISUAL
aHash
|
ffdf9fdff31300df |
|
VISUAL
dHash
|
29343430a6a6c838 |
|
VISUAL
wHash
|
bf87829f131f008f |
|
VISUAL
colorHash
|
07007000010 |
|
VISUAL
cropResistant
|
2938343430a6a6b0,008028603a1a3038,41a09e696192e841,8000423939900800 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 45 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)