Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D4D1941FEB0853250B5201D0B89173EDD35E44AD82B28B966EE8C52C2FB26594F7FBC5 |
|
CONTENT
ssdeep
|
192:hfeLTPmew6mZmdtmzmPmxbA7YZ3z9ktCjVCHrAh:hy7nw6I2t2+mbAw3RktCpCHrAh |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed2992366e6b092d |
|
VISUAL
aHash
|
01effbb1f3ffffff |
|
VISUAL
dHash
|
9b1893636796cb78 |
|
VISUAL
wHash
|
01c7c381b3037f3f |
|
VISUAL
colorHash
|
070000080c0 |
|
VISUAL
cropResistant
|
9b1893636796cb78,017686d6f4863601,468f1b255b370e9d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)