Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11243FAE63855B4160B7290D3A0AF3A4AB339182FB91C55A0B174CFE531F88A5606BF5F |
|
CONTENT
ssdeep
|
768:UyWuPWy/L1u5/u15/8n+sLv9CN6ZDSI5M6zqFvSj6BzWHlFFqX8Uxz23yP2CWKn5:HsdyOloQzZs8oWQbp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ee3139ce9ac311c6 |
|
VISUAL
aHash
|
81818181b9b9b99d |
|
VISUAL
dHash
|
2323036365616179 |
|
VISUAL
wHash
|
818181b1b9b9bdbd |
|
VISUAL
colorHash
|
1b000e00000 |
|
VISUAL
cropResistant
|
0000000000000000,0000000000000001,8280c1999dc080a2,36a3a3a1a1a181a1,b08a63737f7c767a,c0c0c0d4c2c2c2f4,4fcd539b9f97938f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 700 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain