Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13AE3D8B0F120987D42AFD1E2F376BB1AA2DBE306DACD07D6D1E947A80596D64FC13046 |
|
CONTENT
ssdeep
|
1536:u2BBzGS1GvEZLbHNvWlt70GT46XBGZvmza:u2BY8bHNvWb0GT46XBGZvB |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b84547511f926dcd |
|
VISUAL
aHash
|
0000c3cfcbc3cf81 |
|
VISUAL
dHash
|
f023273e939b9823 |
|
VISUAL
wHash
|
0000d3cfdfc3ff81 |
|
VISUAL
colorHash
|
0e200098000 |
|
VISUAL
cropResistant
|
fe00c070300000fe,232f3c9b939d1d23,2c3233ec00d26969,a6a4d4d4a4242531,e4e6d99d74793959,b694d4d434353535,c6450316272d3253,7f7f7fdcd47f7f73,35508aaabe154031 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 69 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain