Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T186227333A600DD6A8D9B56C8F2C09589515ED349FB3148CBB2B091BF3BC0DF165A93AD |
|
CONTENT
ssdeep
|
192:udTlJxhMcnthWeNWbwi1VsWmbvVfMmUU8VCoJ+:Sfi1VsWmbvVfMmUFCoJ+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b5607c28f23cd3a6 |
|
VISUAL
aHash
|
c3c3ffe7e7ff81ff |
|
VISUAL
dHash
|
1717080e4d323700 |
|
VISUAL
wHash
|
8181e4e4e78381fe |
|
VISUAL
colorHash
|
07201018000 |
|
VISUAL
cropResistant
|
1717080e4d323700,7c6e00006a6a3028,41900cb2b20c0000,8000d4d400696000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain