Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10DB3B622F1A0213B104BCFF9B552A3E430CE57EAD6479495E568D2E63B86CE0FD43B46 |
|
CONTENT
ssdeep
|
768:aTULTJDFT/AoqBKL70Ir8bmBfmMvVkO0J+zY3mU6fSRFw6pdrz6GH7yIO:YiJpbJjPbYSFmMN5qOrL6DBp+JIO |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ee445e514753565a |
|
VISUAL
aHash
|
00d3f7f7ffff8db5 |
|
VISUAL
dHash
|
f43727470e885575 |
|
VISUAL
wHash
|
00d3d1e1e3fe85a5 |
|
VISUAL
colorHash
|
06007008000 |
|
VISUAL
cropResistant
|
808082a2a2828080,372705478e595575,d0d0c0d0e0039806,1f414342c686a2a2,1633338686232217 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain