Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1335234308C51152F021743C9FA27AF9A61C3A141CF761991A6EC139F76DEE6BCC6B2E4 |
|
CONTENT
ssdeep
|
192:XZuzjStHoHF/4UmAoPOD6NBfw1YodG2snWVh0meFek3Sja6WB1wJNs/RNtxBiVtk:oFwUmAoP8mMV0z |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
918e6e916d916e8d |
|
VISUAL
aHash
|
001c3e7e7f7f7e00 |
|
VISUAL
dHash
|
f8f8f8d4d0d8d8d0 |
|
VISUAL
wHash
|
001c3e7e7f7e3e00 |
|
VISUAL
colorHash
|
06206040000 |
|
VISUAL
cropResistant
|
f0f8b4b4b2b0b0b8,f8f8f8d4d0d8d8d0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)