Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E93232377044C52A4EDB41EDEAC8F299A55DC146F73084836AF5426FAB80DFD792132D |
|
CONTENT
ssdeep
|
192:n+5SIThY1HJ4kjDTaHuHYH74HzHs/+H6HVHXH7IsHiH5HlHdx0GeWQffMmUU8VCl:+0p4KDaaokzs/K2BX77OFx73TQffMmUq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b978c68c699196e6 |
|
VISUAL
aHash
|
8181c381c3ffffff |
|
VISUAL
dHash
|
2b0f0f1f0b60ffc0 |
|
VISUAL
wHash
|
81818181819fffff |
|
VISUAL
colorHash
|
17e00008000 |
|
VISUAL
cropResistant
|
2b0f0f1f0b60ffc0,ec8e99a9a8b13133,49300c0b1a1b1b5a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 1 other scan for this domain