Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T107B15831A884963312A3C9D0A371BB3F62D2915DCE331B57E3F9475D8B86EA7DC02645 |
|
CONTENT
ssdeep
|
48:d8JpQzcbkXSAlujwgLq80NUtFaJWdMYqW1YVWAYDVWaY3WWMY/WIY4WSYrWMYCZ/:d3UpAj1oaJHNs8zy/UWLsZTnI1NKC |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c334476c1b3dd313 |
|
VISUAL
aHash
|
003c2c081c7c383c |
|
VISUAL
dHash
|
60e9d9d8b8e84949 |
|
VISUAL
wHash
|
007c2c3c5e7e3c7c |
|
VISUAL
colorHash
|
00000000c00 |
|
VISUAL
cropResistant
|
353663a3a58e3e3f,32b2d4d469785634,6c6c5a5a6a668c9c,d2b232b2b2babab2,9ebaa2b8c8be929a,60e9d9d8b8e84949 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)