Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T159A1713150898E3B112263C5FFE92B5AF2C2A0C4D9571F44DAF9823D8FEEE24C856589 |
|
CONTENT
ssdeep
|
96:vfsSwlabfCwvGkyFecnDfqVLx0kbVZBjCMp:vfTw8f9mNnupvCU |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
eccb93349c9b6286 |
|
VISUAL
aHash
|
fff3f1d1d1c1ffff |
|
VISUAL
dHash
|
20a3e3b3a7876212 |
|
VISUAL
wHash
|
ff10f1c1d1c18bc3 |
|
VISUAL
colorHash
|
07400000180 |
|
VISUAL
cropResistant
|
20a3e3b3a7876212,99993db11d1c15b2,36272575e96d6458 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 12757 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain