Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16C53FAE938946456076290D3B0BF3B4AB739186F791C15A0B0B4CBE571F88E5606BF4F |
|
CONTENT
ssdeep
|
768:ayWuPy1ubWHS/9TH+5/u1zCZzUs8n+5LnRjwqzDv/X/LSLNqIMW5uSF+GQFflcok:UTyOloQzZs8oWQbp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8d2d656d65213d3c |
|
VISUAL
aHash
|
033f1f3f1f1fffff |
|
VISUAL
dHash
|
967276c6766e4a4e |
|
VISUAL
wHash
|
033f0f3f031b2727 |
|
VISUAL
colorHash
|
07000000c00 |
|
VISUAL
cropResistant
|
967276c6766e4a4e,0000047871792916 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 469 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain