Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F771DE70408AF97F018396E49F35AB8AB7C9C345CF230B0682FD965E2FDAD81CD65958 |
|
CONTENT
ssdeep
|
48:OfGcC97INcBlhfRKtbTvSbb0e3AKWvKaHtXoeadnojWSQlhfMWHZrw:4Gb9sN6R6bTv6t3AHvJFaaj4Mwrw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b3330c0c3f2f2d1b |
|
VISUAL
aHash
|
00efc7c3efffffff |
|
VISUAL
dHash
|
ff488a8e58260800 |
|
VISUAL
wHash
|
0004c0c0c7f3ffff |
|
VISUAL
colorHash
|
06006000000 |
|
VISUAL
cropResistant
|
ff488a8e58260800,fffff7efeff6feff,2d26262765616bc3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 3 other scans for this domain