Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A1F1EAB07691157B722B46FFF1202F79B4E9CA4FC643AE96B3B885D0D784C604A25B42 |
|
CONTENT
ssdeep
|
96:Tk9MQ+St3jJDO+gZxhzTpTwLxxMTPkNTpI39qtnD6Jqtmw/hjtGaK8:YMdStFDHgnlGLx8zctnD6EtmUhjPK8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b86e591d47195b4a |
|
VISUAL
aHash
|
00c1c1ffffdfdfff |
|
VISUAL
dHash
|
f0ada585e19494b4 |
|
VISUAL
wHash
|
004141557f4f4f5f |
|
VISUAL
colorHash
|
06006008000 |
|
VISUAL
cropResistant
|
4000c06060600000,adada5b59594b4b4,91b0b0f093655550,415171717e547d1b,1349c9c1c8893307,434dd9d8c4c55343,872143498d651903 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 42 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 3 other scans for this domain