Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BCD204A28D5A40DBBB15B2D090172E79EC81CC3F52A24A4CE5BFD6E0F7B69D1D60E344 |
|
CONTENT
ssdeep
|
384:IHjHvu0ep71DPtudIw1DOhDtWhxycBchCg1m:IHlep71DPtoKDtWhPBchdm |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c2c2c7e4ac35b1ba |
|
VISUAL
aHash
|
787c4c00f94000e1 |
|
VISUAL
dHash
|
c5e8998393950a8b |
|
VISUAL
wHash
|
7a7c6c00ffe100eb |
|
VISUAL
colorHash
|
31401008040 |
|
VISUAL
cropResistant
|
c188b09091941911,7666eccce5e8e0b0,9a983b33eb666a99,e9a98dfabcdeb979,99b6b69888cc72b2,c5e8998393950a8b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 1 other scan for this domain