Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18DF110E0C554EE37435285C5A7B16F1BB392C389CB570940D3F883AB9BCAC60CE665AD |
|
CONTENT
ssdeep
|
96:nkuGe2WSzeFvMSSAuSTCctkZtQISS8ct74HTW0FduXGNwvF8epXsg/7t74eWcYff:k8XSzeFdVWcwtQWYTWmK2gzHWcsuA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9a5da1c2c18d9e1f |
|
VISUAL
aHash
|
ff001c1c1c1d1f0f |
|
VISUAL
dHash
|
a85e393a3135bb1f |
|
VISUAL
wHash
|
ff001c1c1c1d3f0f |
|
VISUAL
colorHash
|
03000038000 |
|
VISUAL
cropResistant
|
a85e393a3135bb1f,a1ababa94b5b5b59 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 113 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain