Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T115521DB18064CD3310ABD2D052B5AB1F73C5E368DE978B4263F893196FDBC45ED12A68 |
|
CONTENT
ssdeep
|
192:fSDNmpJ0KQ3CzpKTW5D5QjthwfAVpjLATmzPqdmQtq/m/q0m+qYB4o:fSYpJZ9Mf2KpMC7dOb/w+J |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9c9c936363618acf |
|
VISUAL
aHash
|
ffbdbd81c30000ff |
|
VISUAL
dHash
|
aa322a9686b23008 |
|
VISUAL
wHash
|
ff9d9d81c30000ff |
|
VISUAL
colorHash
|
0e200030002 |
|
VISUAL
cropResistant
|
ca8a22c8aa8c8c8e,aa322a9686b23008 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 4 other scans for this domain