Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T154914FA0967749FB1083CAD07AD59F5AE1C4E3A5CBA71A58A2ECC12F28D7C00EDC5370 |
|
CONTENT
ssdeep
|
96:T6jrP7Hxq0WiJ55YtmcHejqgLFySDWL4E:eQ0WiJ55YtGEL4E |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9c9d2636c97236cc |
|
VISUAL
aHash
|
1818181818000000 |
|
VISUAL
dHash
|
323232b232323565 |
|
VISUAL
wHash
|
191b7f999b8181b3 |
|
VISUAL
colorHash
|
07001000180 |
|
VISUAL
cropResistant
|
8e8eaa86869696a6,323232b232323565 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 10 other scans for this domain