Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14DA3F8A078C55A391A93B3A06734FAC1B76AF345C35BCB4C93B4825B77DAD81C80D6B4 |
|
CONTENT
ssdeep
|
1536:/ivR5t0Wi6Lc44WDRwJ0Cr89eIMumuxW+QzbFHfe50ityq9V:R34Htfc9ofQzZHGuG |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
aa1af4f5110d1cde |
|
VISUAL
aHash
|
00a10001fffffbff |
|
VISUAL
dHash
|
9c4d692ba9372314 |
|
VISUAL
wHash
|
00800101ffdff3ff |
|
VISUAL
colorHash
|
06002600008 |
|
VISUAL
cropResistant
|
9c4d692ba9372314,0000106a6d651000,8181619191010181,8382212143439286,5c26e627474d1387 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 31 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)