Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DCA1FE61C345D85A7215C4B0F7B27B5E3B80418AD7071B7892F0A379FEC8CA259963DC |
|
CONTENT
ssdeep
|
96:A3JVTD+FpjlQzAcjkAcmCAc4DAcBGAco+F7ne:A3JV+WzAekA/CAtDAwGAd |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b8cf44004a6fa76f |
|
VISUAL
aHash
|
391fbf9d5d0f800e |
|
VISUAL
dHash
|
e3bb5b31b1bc34b4 |
|
VISUAL
wHash
|
795f9f9d580f8006 |
|
VISUAL
colorHash
|
13400000180 |
|
VISUAL
cropResistant
|
3f9e93d1cac0f39c,d2b6b362e2e2e272,840e0e9e9d29d3f1,00caf0f4d8d9f2e2,8083b08ee1388ee3,e3bb5b31b1bc34b4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 6 other scans for this domain