Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D6C2087183801EBBA243D3D87572561373C9D27ED7A2A601C6A0C7A86BD3DE4DC6D09D |
|
CONTENT
ssdeep
|
768:Raunte+mm6T+TJ+e8oFOkZDOEBuhjvMWYfhSVJMBJ:RJntjmLk+e8IZchd1MBJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
82e95f244877457e |
|
VISUAL
aHash
|
007f7fff7f3e0c3c |
|
VISUAL
dHash
|
dde9e8e8a8e8e8e8 |
|
VISUAL
wHash
|
003f7e7c3e3e043c |
|
VISUAL
colorHash
|
07241001001 |
|
VISUAL
cropResistant
|
cde9e8e8a8e8e8e8,0224c4c4dccc4424,dcde4db0bc9c191b,232e0da529894470,a4e4c44049486a32 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)