Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T164A17427E185761A0B974329BEA6B3CDF2330485D1186EA856BF430F1BC4DE6C0379E6 |
|
CONTENT
ssdeep
|
96:TCXG1mXQXfX962Xuo+SyhgOOb7h0Bg2106Po1oYyTck5GUiOFFPr1:oFC/9OQ/b7u06ZbPiQV1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
df40419eaba87c69 |
|
VISUAL
aHash
|
000000ffffffffff |
|
VISUAL
dHash
|
00c0006d6c706569 |
|
VISUAL
wHash
|
00000081ffbfffbf |
|
VISUAL
colorHash
|
06002e00000 |
|
VISUAL
cropResistant
|
0000000000000000,20a7a93359612800,602f6c6070606161,000000c4c0100000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 11 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 1 other scan for this domain