Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1442467B061900696512B0BF1F170B74A558AA34ACAE3A7CCD2FCD3E5B7E7C67AC504B4 |
|
CONTENT
ssdeep
|
1536:IGsfI1+UnodEEbPQDYxpkNnEnm0ueYQMrEzFnWBWPFFxRa7A/kCc0KqdyfqUloX+:IhGwEAHnDi8HGOHjhTyT |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8ce38bc463e6a6ac |
|
VISUAL
aHash
|
791c3f6058161618 |
|
VISUAL
dHash
|
c330e79eb2b4b4b6 |
|
VISUAL
wHash
|
711c7f6f18165e18 |
|
VISUAL
colorHash
|
3000f000000 |
|
VISUAL
cropResistant
|
09094968a9a90909,c46869a4a1f59998,a0968e8f8e968ece,5fc5f1d78e1f8ebe,c330e79eb2b4b4b6 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 9648 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)