Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D70294399058CCF79336CB60B2C2BA1460978261C7021D45F7D8874E77EFED2C555AEA |
|
CONTENT
ssdeep
|
96:NMnG5nqG/4WJBISVz8wxws4fDLsMBpQVjhUFZO5W9za0vyJUTbptWNlkmn07TjR2:NMn7GhI68Mf4HsCm2qdn1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cb3c78622f982cd9 |
|
VISUAL
aHash
|
10381c3e38787c78 |
|
VISUAL
dHash
|
61f0f0eacacad8d1 |
|
VISUAL
wHash
|
103c3c3e7a787c78 |
|
VISUAL
colorHash
|
31007000000 |
|
VISUAL
cropResistant
|
f9fcf8f840f0e0e1,18fce6d6d6ecb833,b87ae0c08589c361,cfde959492c1f0fc,f6e460c8d0a0c081,61f0f0eacacad8d1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 779 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)