Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1765274B0D105693F2AA2E5D155F1EF1566F0C6FADA0621C8D3E86E6D0ECEC60E44E712 |
|
CONTENT
ssdeep
|
192:7lOYJmiiBJyZZyJCtwpiWJDTFUJCpzp5YwJ1+syMYULvGHCPuAYuB5OfG0Fl:7wgbevqwJotFNiPlLyfnFl |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b34c4c334e73674c |
|
VISUAL
aHash
|
00ffffe7efe7efff |
|
VISUAL
dHash
|
cc000c0c4e5e1a23 |
|
VISUAL
wHash
|
00e7c3c3c7c7c789 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
0c000c0c4e5e1a23,004020d2d4d4d220,0008303232321400 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain