Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T133D120709069CC6B014780D8B2319F5E77A1D381CB334B0467F8937E6EE9CB6ED55258 |
|
CONTENT
ssdeep
|
96:TggSlMv76mUWiPvZnvI5vPelvpxvaivx301C5QkyUM5:3GEumLgvVvEvmlvHvVvxEw/yUM5 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
931fcd741d8d5039 |
|
VISUAL
aHash
|
0800000000feffff |
|
VISUAL
dHash
|
7478797938380028 |
|
VISUAL
wHash
|
1c000c0c04ffffff |
|
VISUAL
colorHash
|
160080080c0 |
|
VISUAL
cropResistant
|
0c0c6c8c0cbcacbc,dcdcd89c98989890,3c38980008000000,7474485969583c38 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 3 other scans for this domain