Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C7B36577D058081F030356E862647B9DA3D7924EE9874851F2BC83CBBBD5C52BC6AE39 |
|
CONTENT
ssdeep
|
1536:iFgqqHo6wwUBbXhOXMNKdwMUr9r/mnpHxozTFgaOVpMnbZTFgO4Zj5oqTFgGQ0VV:NMCYWr7Tz+mqa+63 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
846a9ee0f3346bcc |
|
VISUAL
aHash
|
001800247e7e7e7e |
|
VISUAL
dHash
|
d5f0f0c49a92a4f0 |
|
VISUAL
wHash
|
0018007e7e7e7e7e |
|
VISUAL
colorHash
|
01006080000 |
|
VISUAL
cropResistant
|
a6a6e5e5c5e0a020,d2a5a5a54a5a7af0,d5f0f0c49a92a4f0,1f3f1f0f978e1f0f,0f3f0f0f878f0f0f,1f3f1f0f178e1f0f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 74 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 7 other scans for this domain