Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14982417292210037563B5ED670F9A37AA3B2E34FEF4B002482AD476807EFD91B757265 |
|
CONTENT
ssdeep
|
384:DhPJiFuDghg4gEwg+gFrA9OYwRe6seZ58p9tIKvthUnK4sxtXUny4VxtPUnS4sul:DhwuDQJ1w/sA9OY0seZ5e9t7vthUK4sX |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
966968969692d3e9 |
|
VISUAL
aHash
|
8181817e7e7e7e7e |
|
VISUAL
dHash
|
2f2323cce4f4f4f4 |
|
VISUAL
wHash
|
8100007e7e7e7e7e |
|
VISUAL
colorHash
|
060060000c0 |
|
VISUAL
cropResistant
|
2f2323cce4f4f4f4,5a5aafab29aab528,304646b8a9968200 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 3 other scans for this domain