Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1559274B354D8AC136A34C9CD7DE1B71CA9A3C19AD6178CCDE1D8928E3AC5DE2D583221 |
|
CONTENT
ssdeep
|
384:eHgJQJhX3kimVx5CJPSh36xuuFu9+S21IgpDtlmbb42BSP+Oys:hJQJhXA5CJPShKxuuFu9r21IEDtlmbbi |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cd30cfc6329998ec |
|
VISUAL
aHash
|
0000c3c3c3bdb9bd |
|
VISUAL
dHash
|
b8b69694046a6272 |
|
VISUAL
wHash
|
0000c0c3c3fffbfb |
|
VISUAL
colorHash
|
06c01008000 |
|
VISUAL
cropResistant
|
fba200c0006d6d6d,e0c88cc7e6e6e0f2,191bd292d2fa92ab,71514d498c8ea2b2,b8b69694046a6272 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 24 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)