Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1014264301C56B82B104792F8A335778BA395C281CE270A6AA1F9F3995FCDC85CD23D6D |
|
CONTENT
ssdeep
|
96:8lFb1Xr3qPTFGKkYTvMURdtktmtktnKBxbb5UoEtRoBDiok3FGDpkYTvMUR8XB/x:AFRjqbFuQVdKcaV6AyDqFXQVXz/jAWM |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed1c93676c136c4a |
|
VISUAL
aHash
|
00fff3f3f3f3efff |
|
VISUAL
dHash
|
c400262626064826 |
|
VISUAL
wHash
|
0031f3f3f0e0ece4 |
|
VISUAL
colorHash
|
070012001c0 |
|
VISUAL
cropResistant
|
0610262626464826,034434ccc8c83444,63053161616122b2 |
Victim enters credentials into 1 fake form. Form data is captured via JavaScript or backend submission and transmitted to attacker's server for account compromise.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)