Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T152614E33A418697603139AE2FEE3349CC187F7EF9A421CC3B5E1919A57E8DD8912124E |
|
CONTENT
ssdeep
|
96:t35tx9AaizIPkWcvsw/2bkW/pUv0mON1r:V5tx9Aai8PklvswOkggON1r |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c0002fafafd4dcd8 |
|
VISUAL
aHash
|
020010feffffffff |
|
VISUAL
dHash
|
e6c8b0e00c800000 |
|
VISUAL
wHash
|
00000000ffffffff |
|
VISUAL
colorHash
|
07007000200 |
|
VISUAL
cropResistant
|
e6c8b0e00c800000,f7d3cbb6b4b8f0d8,0c7460888888c000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 12 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 1 other scan for this domain