Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1989283767121392702478AC4BD647B5E32A7925EC40720644BFEA3D93BFFCA4B85B316 |
|
CONTENT
ssdeep
|
384:6unL7nL4nL8nL4hK8+8tz+ATkD+2gjq+Binfu5BVf9nLsH+Lyzc1fbf0pGVP+QDy:7fG6mKithk9gjdtsQyzED5Vlu |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
be3ae1c4ccc994c6 |
|
VISUAL
aHash
|
8781878797ffffff |
|
VISUAL
dHash
|
1b0b2c3c2c2c0000 |
|
VISUAL
wHash
|
018187870404f070 |
|
VISUAL
colorHash
|
07c40000200 |
|
VISUAL
cropResistant
|
1b0b2c3c2c2c0000,67cd3a6df5e9cb9b,3c272122a4c490a0,32b2b6b4707c5f2d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 75 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 10 other scans for this domain