Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FA735BB2B520687D839B54DDF37D6B85A283AA0CD9C612C4F6956D9C27D3CB231433B8 |
|
CONTENT
ssdeep
|
1536:aa+EsZ/8LeoxDHMTWuFJ2cOFDTEe+w4MjBowUMjBaYVMjBZb82+/9dtyDiedOypW:aPmbMTWUQ3Iwaw4YQ820D0j0+dG |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ee669968e9916e90 |
|
VISUAL
aHash
|
f1f0f0f0e0f1ffff |
|
VISUAL
dHash
|
a765656565650001 |
|
VISUAL
wHash
|
e0a0e0a0e0e0ffff |
|
VISUAL
colorHash
|
07000000038 |
|
VISUAL
cropResistant
|
a765656565650001,aaa2b43a3bba86aa,fcf833fce06bdcfc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 115 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)