Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C412515221085999D3F346C598006694E243EB8FC970C77056EC4E7B1FE3AA167A2F3F |
|
CONTENT
ssdeep
|
192:PhdeOkzXHjbxIjLZ6Y6Vi0lXjwi6vBiWhQX8Yv9+hiozQJmGW:YzX0UH+vN6ghbzQjW |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9212bc6de92dc1e5 |
|
VISUAL
aHash
|
840e6e04646403ff |
|
VISUAL
dHash
|
2d0ccccdcccc3e8a |
|
VISUAL
wHash
|
840e7e64646607ff |
|
VISUAL
colorHash
|
39000000018 |
|
VISUAL
cropResistant
|
e1d8ac8c8ec3d3c8,a282a2badad280a2,2d0ccccdcccc3e8a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 5 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain