Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EC731E72DC501037116B26CBF97CEB5D61E3C38BFA472281A6F883945BE2D45992BC39 |
|
CONTENT
ssdeep
|
768:hduYxR3ljRG3EQRG3zaRG32aRG3Fzc2v+4t+swQRNUUHRhL:hav+4t+JQjNR1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8283575fc74353c3 |
|
VISUAL
aHash
|
18ffffffff000000 |
|
VISUAL
dHash
|
f8b480809070f0e4 |
|
VISUAL
wHash
|
00ffffffff000000 |
|
VISUAL
colorHash
|
06007000000 |
|
VISUAL
cropResistant
|
c2c2e2e2e2c2c2c2,3aa082a080808000,c0c9e8e8c80a9a1a,1268e0f0d0e4c464 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2600 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 10 other scans for this domain