Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14D23C7317221683702578AC4BA617B4E72A7829DC807216087FFA3D56FEFCE5B817709 |
|
CONTENT
ssdeep
|
768:zekNgUdLKithk9gjdwIY+OLoL+zjOtoYsONo6+NwvV63TA7iTCp1d0bm0tBAVCHg:tthk9gjdwH8+NyV63TA7iTCp1d0bvtBa |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
99c9e684c6ba93a3 |
|
VISUAL
aHash
|
ff1808183e1e0000 |
|
VISUAL
dHash
|
d0d0f0b0f0f43428 |
|
VISUAL
wHash
|
ff3c1c1e3e3e0e00 |
|
VISUAL
colorHash
|
10000030001 |
|
VISUAL
cropResistant
|
4c4cd080d0d0d0d0,e0c0c0889890f080,862e1c9d984de9e9,1a1a2c2959da58a2,d0d0b0f0f0f42c38 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 75 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 10 other scans for this domain