Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14C0312A0CE1CD423591713C15A665F2A7192EBFAD74A1FF248B520F223B9D10B277E2D |
|
CONTENT
ssdeep
|
384:lZJaT1ZqzoMO1EJKv3MxBo7LQ3+ZoDbmhajx5rqbunAbCkE99DY1DMmtunAWDbm0:cq54456Mi5Ep5QlI2Ve9PZ+S |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d51e1c6a63636762 |
|
VISUAL
aHash
|
001ff0f0ffff0002 |
|
VISUAL
dHash
|
6430484a88840902 |
|
VISUAL
wHash
|
000ff8f8f9ffc0c0 |
|
VISUAL
colorHash
|
07000018003 |
|
VISUAL
cropResistant
|
6434484a88820902,3434b03474744448,639898c998d8d825 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 133 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)