Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A6341F32B961183F115BCF8EF43D7FD8A28A8396D35363D2FA50021A56EAF914D3259C |
|
CONTENT
ssdeep
|
3072:e1dM0J0FFj//bRfAOhSmst+olTtj1ppRa3sdmJTR8PvF1tkp1yp1bp13pYLCr69y:e1dM0JYtJs8Ru |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed4d1212161d5b7b |
|
VISUAL
aHash
|
00fb819bffffdfff |
|
VISUAL
dHash
|
e9231333278e3733 |
|
VISUAL
wHash
|
00f18181c3ff83ff |
|
VISUAL
colorHash
|
07206008000 |
|
VISUAL
cropResistant
|
8282c2d2d2828282,2b33333787073723,d0d9e8d8c81a8b2b,5c4326b6361dce6f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2496 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 10 other scans for this domain