Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F123C63309C4ABAB91D342C49324A71BD395C240E6BE879EF2E5831E17CAD45D937F68 |
|
CONTENT
ssdeep
|
768:gt9AwtD0wkXZ+Tm0jO/EbJbkmQyKgzJnjRR4RVwp7N9Wb:gt9AwtDvkXZ+TTjO/0TKgzJncVwp7N9q |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9414ebebcacaca86 |
|
VISUAL
aHash
|
fd06060606fffff9 |
|
VISUAL
dHash
|
71cceccccc3c3313 |
|
VISUAL
wHash
|
fd060606060efff9 |
|
VISUAL
colorHash
|
0e000000180 |
|
VISUAL
cropResistant
|
00018961618901a2,96d6e8b294710f8e,c0303c2f33535313,b8e0c0f0f0e2e2c6,ccccecccccccccec,f3f161e1e3c3cec7 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 174 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)