Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CA43072585935F3F0A734DD666F0972EE2824A4CFB87576953F4D3DA0BFAC408D1A029 |
|
CONTENT
ssdeep
|
1536:5ibEGskYCsY7tLnYBfnbgcffnunCyueVRZqOcz:5CTY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9616e929e96d06cd |
|
VISUAL
aHash
|
000606060606ffff |
|
VISUAL
dHash
|
9ccccccccc8c5600 |
|
VISUAL
wHash
|
000e2e0e0e0effff |
|
VISUAL
colorHash
|
320000005c0 |
|
VISUAL
cropResistant
|
66664672c05a7396,246565880010080c,e4ccccccecccec9c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 24 techniques to evade detection by security scanners and make reverse engineering more difficult.