Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18A93737996500033246762CAF86DA76E61D2CE8FEE83379555FCC33817E1D4AC92B938 |
|
CONTENT
ssdeep
|
768:hh9lxR3ljRG3EQRG3zaRG32aRG3Fzcvp9hte9eHZzCf4xkJC4Eq5CbePk6GhreBo:hz9hte9e564i04Eq5CbePxSeBejefcr9 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9b4243535357475b |
|
VISUAL
aHash
|
00ffff9f0f9f9fdf |
|
VISUAL
dHash
|
d83ae07838383838 |
|
VISUAL
wHash
|
001f1f0f0f0f8f8f |
|
VISUAL
colorHash
|
07007000000 |
|
VISUAL
cropResistant
|
8080c2d2d2828080,90e0e03838383838,d0d8c8d8e0969090 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2560 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 2 other scans for this domain