Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18FD17135E19015BA32C787D4D2B266C76285874087835EA4D2F893BA5ECFCB0CD95BC8 |
|
CONTENT
ssdeep
|
192:RSyUxcadJNu2n9v44mgoeoQoq+gRaslv4w:N2caE2Ncy3hH |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8f8d31dd25d17464 |
|
VISUAL
aHash
|
183c3c3c3c3c3c00 |
|
VISUAL
dHash
|
7261616861686852 |
|
VISUAL
wHash
|
3f3f3c3c3c3c3c00 |
|
VISUAL
colorHash
|
0f400000180 |
|
VISUAL
cropResistant
|
f4b0a2bbb2839ea2,7261616861686852 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 26 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain