Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1ED9354F61D148E3D01134E8AD6EBE318D389887DB9694C8BCAFF5B76418BD50F4A3864 |
|
CONTENT
ssdeep
|
1536:oodbc2UTtScI3bjiV+EAiHgJsNp+Iozji/beL39YiUiVJPVmCsUYuVkv63S7G21C:oac2KK3DTWb6zNAh3Ps1KNPEc2wV0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a404eeee7b191393 |
|
VISUAL
aHash
|
13000600ffffffff |
|
VISUAL
dHash
|
57a7be9e051c140c |
|
VISUAL
wHash
|
00000e00e7ffffef |
|
VISUAL
colorHash
|
060020000c0 |
|
VISUAL
cropResistant
|
694447a7aafede9a,9390a4666b696926,8280a232b28280d8,821c45181404104c,0002010696064142,47a7aafe9e9aac90 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 17606 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)