Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19943B772B1205C37616BA3D9F455B70692D3E70FCA425BE1E2F8A37A09DAC32F913416 |
|
CONTENT
ssdeep
|
1536:l/4X3yiTdB967PXdVA9NTxJ8mzXGlty7/d+Y:V4XNZB+sNVXGs |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b032924dcf6d65c3 |
|
VISUAL
aHash
|
c7c7c3cfffc3c3ff |
|
VISUAL
dHash
|
8c0f9e1e20860600 |
|
VISUAL
wHash
|
008783c3cf83c3ff |
|
VISUAL
colorHash
|
06000038000 |
|
VISUAL
cropResistant
|
8c0f9e1e20860600,34e1c98d85c94dec,1034b4b4b2b43408,b8b4b4b0d890e1a3,555b5b4959594d45,b1cda5a793896a34,6b2b2b4b09494919 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 181 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 10 other scans for this domain