Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19F72D972516CDD7F61E3C2E8E3B56A2F33E69286CA47031187F9836D1E92D85ED1B090 |
|
CONTENT
ssdeep
|
192:B+Rb3/l3D4z6tDGxUHPGIHs24UWIculjPFK9812ZjymkkrvUN7:sb3d0zyP7savh9g8QjFkGM7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
88083637c9cd6eee |
|
VISUAL
aHash
|
01071f1fffffffff |
|
VISUAL
dHash
|
7ffcf0f0b20c1040 |
|
VISUAL
wHash
|
01001a1d1b6fbf7f |
|
VISUAL
colorHash
|
00000600030 |
|
VISUAL
cropResistant
|
7ffcf0f0b20c1040 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 1 other scan for this domain