Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19D61C7B481018C7E5193CBC8B7A5EF1F62F4826AFF4B0A4462ECE35D1DE6D82EC55941 |
|
CONTENT
ssdeep
|
48:OfGcC97INcWHFlhfRtYKsBzwjvCxWDaHaUewUS8OFTJ7/4YNSWwHskrJi:4Gb9sNPRtYK6gvCIzlC9vPii |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92edec1c457b3816 |
|
VISUAL
aHash
|
ffffcf6c0c0c040c |
|
VISUAL
dHash
|
5fcd19c9cc392d2c |
|
VISUAL
wHash
|
ffffcf2c0c0c040c |
|
VISUAL
colorHash
|
03003008000 |
|
VISUAL
cropResistant
|
5fcd19c9cc392d2c,918cc6d2ba7a4e8e,ffff7f7fffff0303,6496f1b4a6a69996,93190d021c1f0f03 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 3 other scans for this domain