Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T143C2B8712400EC2326DB9AD8B5F29E1A92F5C311C58206D9F5E583F91FE2DBAD733291 |
|
CONTENT
ssdeep
|
384:QcfYxpqdtrj+57Oy4987rnbSrd8hf8EbhrzyrLhJLeYXCjhjhJ/XgThrixhWHpfn:JYrKtf+O9iTmrdvEdyr3N0hMAypawjqC |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
91bb44ac7f900f53 |
|
VISUAL
aHash
|
0ccfffdfbf7f5800 |
|
VISUAL
dHash
|
d919599978e794c0 |
|
VISUAL
wHash
|
008fffcfaf1f1400 |
|
VISUAL
colorHash
|
02006000000 |
|
VISUAL
cropResistant
|
d919599978e794c0,092108a92d290c14,1818181819343434,0080c00000c08000,d2dbd9d2d3d192d2,258c3a66d6b3596c,97decc4922180e0e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 82 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)