Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T198C3C3E062A41E37056BC5F8B915FB25D2D2C19FCB0E98D6E3D582532FE5CB22D0D268 |
|
CONTENT
ssdeep
|
1536:XBBD+paZgjEieV/8TQpzydadhay3ueaiaLavkKTnih:7kMhx20pueb65 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec699392c66d095b |
|
VISUAL
aHash
|
ffd9d9d1f1d781ff |
|
VISUAL
dHash
|
2b333337352e2749 |
|
VISUAL
wHash
|
fd9981f1f18300fc |
|
VISUAL
colorHash
|
07400000180 |
|
VISUAL
cropResistant
|
2b333337352e2749,09511483317b7668 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6779 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)