Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CB913024904A5C1A028387E46E76734E52AFC34DD613270126FCC3AD6FD7ED9EC0A6C5 |
|
CONTENT
ssdeep
|
96:LUuSu88888888888sdoQP/yvuq/riA9OiN/riA9OiA4jCUb1vVHsf:JSeP/yvu5A9OdA9OnmvVH0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f06b9af0f0710f07 |
|
VISUAL
aHash
|
c0c0c0c0c0c0c0e0 |
|
VISUAL
dHash
|
9192161696909090 |
|
VISUAL
wHash
|
c0c0c0c0e0f8ffff |
|
VISUAL
colorHash
|
020000001c0 |
|
VISUAL
cropResistant
|
9192161696909090,2d2497a6929651da,90928c8c8c0c5185 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain