Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B693D9B180449C3794D3E6D096719F6F72CAD38ACE1B1706A7FA839E4FC6DA1CD161A0 |
|
CONTENT
ssdeep
|
768:8IyNJCu+3EQgxX8/WTV5C+16yUCjZowgwcXjCCCJVNO9cEi3AYIkEz9R5ACJnIIO:AJCQ9/JogvUgZGACJcUXcjX8uNaY/9Pl |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ce80317b8be0e6ce |
|
VISUAL
aHash
|
7f7effff3c000000 |
|
VISUAL
dHash
|
48b4e4f561484169 |
|
VISUAL
wHash
|
ff7e7f7f3c000000 |
|
VISUAL
colorHash
|
30600030000 |
|
VISUAL
cropResistant
|
041a5a9a981a5a04,fd39bc6cec6c1c5e,4f4bbb84e4a6585c,7e3e5e7e3efae0c1,e8e8d4d651d3ebeb,3871eaf4ebe3838c,4120b230c8410141,c8b4e4f5614c4969 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 214 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain