Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BC51EF71A0945F339283D288B6E1A74B32C18783DE5A5B014BF697CE0FA7EC4DD1A186 |
|
CONTENT
ssdeep
|
48:vHmnLCwFNGcm2WW8CCRuurAHwHCIOcr4ul30u3YQmBiPjDDj0WrdGsHeG:vHmLBFN37WWY8upquJ7YBi0WrsE |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d9dc226a8f998c33 |
|
VISUAL
aHash
|
b8e05c98a3590d26 |
|
VISUAL
dHash
|
6084b0326bb3d9cc |
|
VISUAL
wHash
|
f8f4da98a9590d26 |
|
VISUAL
colorHash
|
07001000080 |
|
VISUAL
cropResistant
|
6084b0326bb3d9cc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)