Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19EB3FF634256392B0437C2D13465AB3BD1E6D98BFEE74A015EECC7B72BF9C90744A218 |
|
CONTENT
ssdeep
|
1536:XHSrpR4nXBKpSpFl26vKOvqdtL3GlLNoW4:XHS1UMnOe |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bcbc1347e413bc64 |
|
VISUAL
aHash
|
ffdf9fdff31300df |
|
VISUAL
dHash
|
69343430a6a6c838 |
|
VISUAL
wHash
|
bf87829f131f008f |
|
VISUAL
colorHash
|
07007000010 |
|
VISUAL
cropResistant
|
2930343430a6a6b0,0080286038183038,41a09e696192e841,800042b0b0150800 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 43 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)