Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T131F34072B4012D7F6787BD96A52A7F05F2618235F40B1798FBA5090E4FC2FF99226324 |
|
CONTENT
ssdeep
|
3072:l8H4k6IZz6QeZWDOcRk36Izr9UrHyKzNd5T/gV6aSRhvHsh4m+usbiFLjdyzf2R6:l8H4k6IZz6QeZWDOcRk36IzrgHyKzNdV |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e242e6fe9d1818d5 |
|
VISUAL
aHash
|
e1200049ffffffff |
|
VISUAL
dHash
|
a54dd59308ab2a2b |
|
VISUAL
wHash
|
00200001ffd7ffff |
|
VISUAL
colorHash
|
06e00000000 |
|
VISUAL
cropResistant
|
a54dd59308ab2a2b,3731b1353d2d2d8d,c38d9c3c0d0f0f07,f47c1d2f3676a699 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 198 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 10 other scans for this domain