Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19B8121B2B4549CF79043D3D9627877773192E189CE86024462EC83788F93EDAFC6649D |
|
CONTENT
ssdeep
|
48:TfUo77eLB6+rgP3polZe+8d2N/kMiQ5afK2ukFqxUf00b+0XXkpXp/FtNLup1/Rk:Tco3ewmgPZoPePjhJK2u9UA0X0Vp85k |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ff7ffd7c80088009 |
|
VISUAL
aHash
|
80800000000000ff |
|
VISUAL
dHash
|
3008400000000092 |
|
VISUAL
wHash
|
ffffff00000000ff |
|
VISUAL
colorHash
|
38000000e00 |
|
VISUAL
cropResistant
|
3008400000000092 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 33 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 1 other scan for this domain