Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1058211F0A7DB82370573D1C06A7FDB6573C1925CC68B16095AFE93980BCCE17B81A25A |
|
CONTENT
ssdeep
|
384:fSAmQUiM0LUroNqWUKssqfUu3UrUNUx0/2hNW1zCg:fZvqoNfrssu/3Y8K09L |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b34e39e6b1cc990c |
|
VISUAL
aHash
|
ff0000ffffffffef |
|
VISUAL
dHash
|
086868080d4d0c1e |
|
VISUAL
wHash
|
e70000e727270703 |
|
VISUAL
colorHash
|
06200000180 |
|
VISUAL
cropResistant
|
000808000c4d0c0d,0c0c4d0c0c0d1c1e,4d0c0c7171306900 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 5 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 10 other scans for this domain