Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EBF1FBE3914C64051622DA80B9C2F684F277CF02CB1D4836F5B66467B6DDAF4C177791 |
|
CONTENT
ssdeep
|
192:LYbWN1pUmWN1pUvYy6+FOvyAiGYVmgzldgfyds8dPVIq:LYbC1plC1pgYy6xyASmgldgfye8dtr |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a258f3741cb79c26 |
|
VISUAL
aHash
|
0000000700ffe7ff |
|
VISUAL
dHash
|
a983f9ecefcecece |
|
VISUAL
wHash
|
00001d0701ffffff |
|
VISUAL
colorHash
|
030020001c0 |
|
VISUAL
cropResistant
|
a983f8ecefcecece,512c2a492989a193,16080be4e4138000,0000002000040484,ffffffffffffffff |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)