Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19B51873210058E372042CEE4F7A9977FB4E58140D9570E2576FE83ED1F98ECAD835540 |
|
CONTENT
ssdeep
|
48:nOK5foIrcCoCtusccLfL7/GDHQPG2XhI7aKNlZv4AHHu:nOIHrbntgQRXOnlZvA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9ce3c29ca3f28d4a |
|
VISUAL
aHash
|
ffffe1e719181800 |
|
VISUAL
dHash
|
b6398b0f333231a3 |
|
VISUAL
wHash
|
ffffe5c719181000 |
|
VISUAL
colorHash
|
00040003200 |
|
VISUAL
cropResistant
|
363737bdbcb935a9,8b0e3b33323171a3,9c3cf8f8f8f8f3c1,9b35350a250a0a2d,6aaaacdc425fd97d,c5e1f58be8f494f9,62869604072d7963,234b962e3c7c7c71 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 19 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 3 other scans for this domain