Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A75133A0C1049C8B74EB9529B8E573CCC0456624F3AAAF9C729FA7A673D7C7305720B1 |
|
CONTENT
ssdeep
|
96:TGv6xFsnZuPf1uTY8UWCS6R7S4f8Y8UWCS6nVVY5vq/1B:avG+nZuPteY8UWCS6R7cY8UWCS6nVoY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f0c8c8c90ef43be9 |
|
VISUAL
aHash
|
f8f8e0060cc8c4c4 |
|
VISUAL
dHash
|
b181994c55199c2c |
|
VISUAL
wHash
|
f8f8e4a68cccccc4 |
|
VISUAL
colorHash
|
022010000c0 |
|
VISUAL
cropResistant
|
6d6d693933869c41,f9614a4a1a12b3a7,861e616129313058,8787a061627c399b,854c667278784dcf,878f0f0f1f9f1f1f,a1819accd5189c2c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain