Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C9F2B59A31041595C2F38FDC98106A547246EA5FC9714270C2BC8E3E6BE39A5B788F7F |
|
CONTENT
ssdeep
|
384:pGOze9sPHFpWNKZTKwhFKTHFVWWUKMOKBcKPg3Hl8BoEepDbO0vsFijYK/M94UZf:lPHWU94HLHAHGJhs4jY7yUjJoH6ivPX0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a5d20f5ae12d5a8d |
|
VISUAL
aHash
|
00ffffffff000000 |
|
VISUAL
dHash
|
140e001696720206 |
|
VISUAL
wHash
|
00ffffffff000000 |
|
VISUAL
colorHash
|
1e0000001c0 |
|
VISUAL
cropResistant
|
1606141c0c200404,4c0c000e00969600,8c88c82b2baa888c,0080004040800000,100c32b2b2080000,0384361606061606 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 37 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain