Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11B02E01321086565C3F34C9998113994A142DB8FC8219B709AFC4E7B1FD2EA1BBE5B7F |
|
CONTENT
ssdeep
|
192:u+Q67qJpVbdrHjbTIjLZ6/j/jryEP/1xhGjwgu/d1RnZO2sRX8Yv+hHSYO:DMJpVRr6YaGVzT14Fm7hS |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fcad23c62dd29305 |
|
VISUAL
aHash
|
ffd3ffffffff0000 |
|
VISUAL
dHash
|
3327163626002806 |
|
VISUAL
wHash
|
ff81cbcbdbfc0000 |
|
VISUAL
colorHash
|
0e000000180 |
|
VISUAL
cropResistant
|
0023371636261628,2000486272480050,0008060606060606 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 5 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain