Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D2F12794A008AEFB8053A9FAD3E1EE1B31D18117CA51499001F457AEA7D4CC1C7BBDF8 |
|
CONTENT
ssdeep
|
96:TcBIBsSuO1ugt+DZG6Zjwlv0O2AU0rdASH0PPLA5:4Bqrugte9W92qrKSj5 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c31d3ce3e31c1c63 |
|
VISUAL
aHash
|
0020187860303001 |
|
VISUAL
dHash
|
50c8b0d4c8a4e4c9 |
|
VISUAL
wHash
|
18607c7e7c7e7061 |
|
VISUAL
colorHash
|
38000e00000 |
|
VISUAL
cropResistant
|
72e3c9bcb0ac6032,50c8b0d4c8a4e4c9 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 7 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 1 other scan for this domain