Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12212A9B0928069FF015795C96337BB2A32D08BA5DBC20B4922FC47995FDEE85DC6724C |
|
CONTENT
ssdeep
|
96:nU927a73Enf5h0ihfjakjaDpkbwSl6ez3vPzDmVSJSJSTLNx4NdnNZXr1vZKh9k7:nU9TDSlNz3vPzDR44/NylZ5em7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cede646d64349c34 |
|
VISUAL
aHash
|
103c3c3c3c3c3800 |
|
VISUAL
dHash
|
f0e8f8f0f0e0e8f0 |
|
VISUAL
wHash
|
3c3c3c3c3c3c3c3c |
|
VISUAL
colorHash
|
010000001c0 |
|
VISUAL
cropResistant
|
f473d2b695d6b0f4,96b2b2b2b2a2b282,f0e8f8f0f0e0e8f0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 81 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 3 other scans for this domain