Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11C4363328044A4370633D3C875762B3AE293860FD7E30D5556FC87AF6BC6DE18A6B169 |
|
CONTENT
ssdeep
|
768:T+j3wlJhBWX4TiZY02qWjLfpKeSj12sZSmF:qrwlJh44j5HjLfpMssZSmF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9115ea6a486e7f91 |
|
VISUAL
aHash
|
000e0e1e0e00ffff |
|
VISUAL
dHash
|
dadc787c983f0f02 |
|
VISUAL
wHash
|
000f0f1e0e01ffff |
|
VISUAL
colorHash
|
03201000180 |
|
VISUAL
cropResistant
|
d4d4f0f0f894d4d8,b64a2ab522a92956,191b0e8832323333,93dcd8787498381f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 301 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)