Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CF421253120C56A6C2F24999540426C07187E68FC9A0CBB0D6B94D3F2FE6F9167E2B7F |
|
CONTENT
ssdeep
|
192:YfO6pQ/Hjb3IjLRAUvvDjwgzAe1qt3P81jwgzAeIndjfK8rsg/jwuA3JeonZO23Y:CQ/eRigzw5gzGZrWuV44y+OhA1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec6c939393989393 |
|
VISUAL
aHash
|
f3c3c1d3ffffefff |
|
VISUAL
dHash
|
2727272614191d04 |
|
VISUAL
wHash
|
81c1c1c3dbffccc0 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
2727272614191d04,214539cce868c2d2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 5 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain