Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D023A67261211833617FA2D9F555F70191D3EB0FC6826BE2F1E863760ADAC72BD0391A |
|
CONTENT
ssdeep
|
768:ewnpBTXWoZr4NWd5A6L9FwvGWxGGHSby2/m7PrvrvEl3t6jhvBRnddiEK:3p9XWoZr4Qd5A6L9FwvGWfHSAjMFaXnA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b03014cfcfc76761 |
|
VISUAL
aHash
|
c7c3c3c7ffffffff |
|
VISUAL
dHash
|
ae1e8e0e303e3238 |
|
VISUAL
wHash
|
028383c3cfc7c3cf |
|
VISUAL
colorHash
|
07201400040 |
|
VISUAL
cropResistant
|
ae1e8e0e303e3238,d8b4667a9ad09098 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 222 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 10 other scans for this domain