Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17D21F45000585C769182E4EC27D186153899C25BCF5305005BF4CBAD6AF3F8ACE775D5 |
|
CONTENT
ssdeep
|
24:hAXIlvaMmxJRqN9uzXpixPoY0AlpNYN9tuXR6AZS:FvIxJYHMAP9ZYHERk |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9cc90f3e3823279d |
|
VISUAL
aHash
|
19fd7e469e141e00 |
|
VISUAL
dHash
|
f3b3f0bc3c2c7032 |
|
VISUAL
wHash
|
1bfd7f469e043e00 |
|
VISUAL
colorHash
|
07000018009 |
|
VISUAL
cropResistant
|
fff3b3b3b2f1a894,f8f8f1f0a32323a3,f8c8889c9ca868d6,ffeff3f3a8b0b1f3,f0bcbc382c6c7036,1108303232300841,e6c6a66e94b484ae |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain