Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17F9354607953683620AF51CFC22B071D72C1DBC9EA5367E951F0C3685AFAC90BFE61A4 |
|
CONTENT
ssdeep
|
1536:XBG7O6rpswrJ4dOP8jlcxglJuGJTnJJUJiI/dVATGTDF5bTJjcTXu/sF:X6oOPO+onUUI/dVAd |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
88dd2335aa37899d |
|
VISUAL
aHash
|
1d383c183c180001 |
|
VISUAL
dHash
|
71f07070703254d1 |
|
VISUAL
wHash
|
7f3c3c3c3c18183d |
|
VISUAL
colorHash
|
38000c00000 |
|
VISUAL
cropResistant
|
71f07070703254d1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 57 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 1 other scan for this domain