Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13C23B83A61113A3E91174FA8F651FB35618B834ADA47D658F2BC53F22BCEC859D132C4 |
|
CONTENT
ssdeep
|
768:2nK2eVkaW0jK0JbLyyPjDk4ngogyUAI902/R/5Sg6/Mu9A7PvIP+8PZIParP4TPk:ueYtkgT99b5S7aPQPJPqP6P0POPdP4GD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc4e929385a5b5b9 |
|
VISUAL
aHash
|
f0f0d0f0faffffff |
|
VISUAL
dHash
|
41212222223b4239 |
|
VISUAL
wHash
|
e0808080e0bfffff |
|
VISUAL
colorHash
|
06e00000000 |
|
VISUAL
cropResistant
|
41212222223b4239,4743cf9cb0342c68,47673963873f6363 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain