Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16F512C3190046C3F9183D398EBA1AB59A6CAC222C9271A06B2FCD35D6ED3D42CDA45DD |
|
CONTENT
ssdeep
|
48:1GVGcC97INc+hcwfBPcLdvuaHWYfOBs4adBadxf2:1uGb9sNPhhfBPsdvuT+dwdxf2 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b3e219cc1ce637c8 |
|
VISUAL
aHash
|
7effe7e7ffffff00 |
|
VISUAL
dHash
|
8c294d4d3008001a |
|
VISUAL
wHash
|
7c642424f3f3b300 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
8c294d4d300c0000,00200c32b2320c30,08831a1a1a180800 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 1 other scan for this domain