Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AAE15674AC89663F42374DCF647FEB2D31DA8107E50AD51086FD82FA17EAC08EC16969 |
|
CONTENT
ssdeep
|
192:gFjVM9IIeqYMpHH+YoFDFEOJQgQOz7j6H9y9bao63PScChDgFy:KC9IIeQHEFxEuQg3z7j6dSjgScClgy |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dd5d778e88a8aa22 |
|
VISUAL
aHash
|
9800989fbdbdc3c3 |
|
VISUAL
dHash
|
220830b2b22a0c4d |
|
VISUAL
wHash
|
9880c0dbdbe7c3c3 |
|
VISUAL
colorHash
|
07000000580 |
|
VISUAL
cropResistant
|
f2e08a33338a80aa,220830b2b22a0c4d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1176 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 3 other scans for this domain