Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AE925CA28D1640DBBB19B1D094172E38ED81CC3F56E24A4CA5BFD2E0F7B69D1E61E344 |
|
CONTENT
ssdeep
|
192:Cuc8mlrgL1jGqxnldGdaU17XwvWZ9WtCCQcYN4PMN:CbiKEMaU1Xwv8gtVY8y |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b6b6a6c0494d559d |
|
VISUAL
aHash
|
77f71600df000000 |
|
VISUAL
dHash
|
cced2cb5918d766f |
|
VISUAL
wHash
|
f7f7f704dd449000 |
|
VISUAL
colorHash
|
1a600010000 |
|
VISUAL
cropResistant
|
c4b0b09a9d1e1e1e,73e9a1b4a48496f6,78ccb0cacae06160,616161617161f1d1,fed0fef8e0f2c69f,acec6b3996909413,61b4f293b9a2d2c3,cced2cb5918d766f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 1 other scan for this domain