Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11F3308106201B76E5C334F74F38A70AAD2AED385E5E2B82DB395825171D3179CB4BCE6 |
|
CONTENT
ssdeep
|
1536:gmq0wA37nM+MsVokM0f3E4trasSQq8Z7U1c/jDBYJ7CHpnFtKFAT:jxYJ7I |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e5649a929b6d64cc |
|
VISUAL
aHash
|
cfc3c3e3e7c3ffff |
|
VISUAL
dHash
|
191606061c1e1c60 |
|
VISUAL
wHash
|
00c3c3c3c3c3cf9f |
|
VISUAL
colorHash
|
07030000000 |
|
VISUAL
cropResistant
|
191606061c1e1c60 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 394 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain