Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17A72007094546536227307ABFB99FF15E3E2CC41DE9E3246F9E983482EEBC50AD07624 |
|
CONTENT
ssdeep
|
192:GF7a+1+PtJgKjMlR/qiWEo+nPnVzyDeyfvyLAjyI+ANHQl2F:GFIPvgXR1o+nPV+vfaLAuI+ANHM2F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ce4ea5a59713b3a0 |
|
VISUAL
aHash
|
ff000008ffffffff |
|
VISUAL
dHash
|
4ea33169601e020a |
|
VISUAL
wHash
|
00000000ffffffff |
|
VISUAL
colorHash
|
06c00010000 |
|
VISUAL
cropResistant
|
3f2fcd131b4242a7,3ab282e2a280b293,69610c3332060a04,42e7b1315d596961 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain