Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E963D8B2B114183761AB93DAF459B71591D3E70FCA435BE1E1F8A37A0ADAC32F913406 |
|
CONTENT
ssdeep
|
1536:h/I1D/Iu+/I3X3yvDBzbIwpxASnut/I8jMD2XJGPJG9NTxJ8mzXGlty7/d+Y:h/I1/Iu+/I3XCdzbIwpxASut/I8GPJ67 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b83030c7c7c747cd |
|
VISUAL
aHash
|
c7c7c3cfffffffff |
|
VISUAL
dHash
|
9e3fae3e301e1c06 |
|
VISUAL
wHash
|
0087c3c3cfc7c7c3 |
|
VISUAL
colorHash
|
07200008080 |
|
VISUAL
cropResistant
|
9e3fae3e301e1c06,c38f1f633d392f2f,34e38b1b5319191d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 180 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 10 other scans for this domain