Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T153B34677D048081F135356E862A47B9DA3D7624EE94B4842F2BC43CBBBC5C52BC59E3A |
|
CONTENT
ssdeep
|
1536:tFgqqHo6wwUBbXhOXMNKdwMUr9r/mnpHxozTFgaOVpMnbZTFgO4Zj5oqTFgGQ1HB:cAC8iorL |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c1bb812e386cccf3 |
|
VISUAL
aHash
|
ff7e3c00003c7e7e |
|
VISUAL
dHash
|
f1e8f8b2d4e0f0f0 |
|
VISUAL
wHash
|
ff7e3c0000383e7e |
|
VISUAL
colorHash
|
08006000000 |
|
VISUAL
cropResistant
|
4c4ca9ab2b495454,343c5573b1c90929,112b7bcceda95959,a28080b2b280a2a2,f1e8f8b2d4e0f0f0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 72 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 2 other scans for this domain