Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C713C836A040A63302B302E5BB19AB9BF3D59118D773171056FEC3DD87EAC16DE3246A |
|
CONTENT
ssdeep
|
768:ixCNHefAofgA00s2nGQDpKttSOJY3vsAUc6ePYGQ:ZNHefAofgANs2nh4twdvsAUc/P3Q |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
963ba6843c963c6d |
|
VISUAL
aHash
|
062c1c0c007e7e00 |
|
VISUAL
dHash
|
ccd8f8fc33f4c4c4 |
|
VISUAL
wHash
|
063c3e3e187e7e0a |
|
VISUAL
colorHash
|
39202000000 |
|
VISUAL
cropResistant
|
cc4d6dd4ea296b98,2e27233232b31f96,55fcae3428aa5555,6d4c8d1c6c94e862,ccd8f8fc33f4c4c4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)