Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T164C14370B0809A2F57D2D7D478716F2E139742C1A500089CA5858BEBC8FFB14C862EFA |
|
CONTENT
ssdeep
|
96:9NaieoOgY8tdrqCMsrNw+8Ytoczx1H9lYFyksm7Lt7t7x7czqdGcLU:uiejTS1rNw/YCczP9KFh16zUhw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
999d66b64de46458 |
|
VISUAL
aHash
|
1effffffffff0000 |
|
VISUAL
dHash
|
70faf373b3cd4d70 |
|
VISUAL
wHash
|
003f3f7f7fe70000 |
|
VISUAL
colorHash
|
0e200208000 |
|
VISUAL
cropResistant
|
f0fbf3f3fbb34d4d,0000000000000000,010020b2b2300001,c070487870486868 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 5 other scans for this domain