Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T110B16631E0466C0B12332495F5D3AB59E183871ED682AD2CB3BC53AA67CCDA0C57AA59 |
|
CONTENT
ssdeep
|
96:TOXaohOUBOeBFCnt+Zv2eGSBrKDhCll/OocJV1/IociRirIKhr3ulcaNR:CKGtB5onmuIBoe/Jcb17ciRbmaNR |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8da92a2a0ee7f0dc |
|
VISUAL
aHash
|
011bfa7e3c000000 |
|
VISUAL
dHash
|
3333b2c071b00f00 |
|
VISUAL
wHash
|
193bfe7e3c1f8100 |
|
VISUAL
colorHash
|
07000030000 |
|
VISUAL
cropResistant
|
0e1c59b264c89020,66d2394dac160305,3333b2c071b00f00 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 42 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 1 other scan for this domain