Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D3C26372D1021D3B22374EC874F5935A30E2E34CED862054A7F947F95FEBC61782AA99 |
|
CONTENT
ssdeep
|
768:OGtX0n8010Sb4ZOeqYeeoevweFzeULPE/EnEJEpEheeGDxm:fi/qs4AeJeXeIeZe4PE/EnEJEpEheeOc |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a9d40ad729d50ad7 |
|
VISUAL
aHash
|
ffffc3c3c3ffff00 |
|
VISUAL
dHash
|
146896969661940b |
|
VISUAL
wHash
|
fcfcc0c0033fff00 |
|
VISUAL
colorHash
|
000000001c0 |
|
VISUAL
cropResistant
|
1468169696612000,3333333333497101,01008b4b47474b83 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 61 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 10 other scans for this domain