Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E2729630D346AD3D3127C2D823F1AB1B2194E1489B5647998BE7427369C7CEACD39DD8 |
|
CONTENT
ssdeep
|
192:FSsHXLYe/IMUvkgMFAbdQ2B6t/Vm/tYAep53ahwm53ahwzs53ahc4Nu3XeJYon5F:FxHXSMIkgMt5KB5Kos5KmHeVJJD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc73b3ccb38c2689 |
|
VISUAL
aHash
|
fe18181818181818 |
|
VISUAL
dHash
|
4832b0b2b2b2b232 |
|
VISUAL
wHash
|
fff838383c3c1818 |
|
VISUAL
colorHash
|
38007000000 |
|
VISUAL
cropResistant
|
4832b0b2b2b2b232 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3003 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 1 other scan for this domain