Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T168A243769241BC2F81D3C2D5A72B72CEB1E2E18AC6928541F5FD935E1FC2EE4C824785 |
|
CONTENT
ssdeep
|
384:/PSCX5mWW7iibh3kH3+3hYHgfVM22Ya5HAENkQU5vWUv:yN/au2gfVM22PgENkQUl |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cbeb3cc51086ad35 |
|
VISUAL
aHash
|
fffdfd7c38300000 |
|
VISUAL
dHash
|
cb3bf9f9d0e2ec8c |
|
VISUAL
wHash
|
fffdfd7c38300000 |
|
VISUAL
colorHash
|
07400000180 |
|
VISUAL
cropResistant
|
cb3b3bf9d9f2e2e8,0d0e0e18f0e185cf,d898b0a0c0808000,0b0b0b3b130b0b03,3b3bf9d9f2e0ec9c,fc87c0cec4d4c4ce |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 5 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 1 other scan for this domain