Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10C1320709459A93B01F3A2E167B57B6EB3C9E2C9D903070427F8C39D8FDAE94ED21161 |
|
CONTENT
ssdeep
|
768:OHAyzdgof/sSONnsL8FNkdQgL7vGoZ1WQ8ymoKko:8AyzdgJn6OoZAQ8ymV |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c74706b8b8b139c7 |
|
VISUAL
aHash
|
ff3020ffff81ffff |
|
VISUAL
dHash
|
4d656189233beeec |
|
VISUAL
wHash
|
ff20200ffd817707 |
|
VISUAL
colorHash
|
100000003c0 |
|
VISUAL
cropResistant
|
8485d3c3e9f474f2,9834fe8eccb8b4cc,f0a437ac6ca1a7c4,d4dab5b53d4cde12,4cce9e8699d9b0a8,4d656189233beeec |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 54 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 7 other scans for this domain