Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CBB1243050404E3F40E786D8B7F4AE1A2293C382D656198876E88BDE6FD7E55CE13BB5 |
|
CONTENT
ssdeep
|
48:GzI7cCGJOA1BI4BQj8+wHU6/nm96AwPDV0j4RIkARHeiDin094:77bGQX8R0gfDjNfB094 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b839c74b38b55878 |
|
VISUAL
aHash
|
ffffcf8f88d8ffff |
|
VISUAL
dHash
|
ba1b131c19914c11 |
|
VISUAL
wHash
|
7b888b8988c8c3ff |
|
VISUAL
colorHash
|
07400008080 |
|
VISUAL
cropResistant
|
ba1b131c19914c11,2e672d253319590f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 7 other scans for this domain