Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D273A771D4A4C47706CEB7E0B6252B1F7693C79BC9820BA6E7F843082E85ED2ED13459 |
|
CONTENT
ssdeep
|
1536:bzMMgMk6dqAGFwpdLX3fl2gMk6dqAGd2SQoIYWu2y8sELJGsKMVS2hs9hpMwjkj4:PMYO2 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e4130e1b5e716735 |
|
VISUAL
aHash
|
0003c3c3c3c3c3f3 |
|
VISUAL
dHash
|
49368e86168696a6 |
|
VISUAL
wHash
|
00ebc3c3c3c3c3f3 |
|
VISUAL
colorHash
|
0e0002c0000 |
|
VISUAL
cropResistant
|
d8a434489296f84a,cedadb4eccd19696,8cbe3e16736b3317,e323337364686464,49368e86168696a6,a7ab395572385c28,2b335111d5727050 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 59 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 7 other scans for this domain