Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16E052AC61371A79978C7D15CEF33CD98A31B909D9AEEE1C492AEC644688BCC0F61D9C4 |
|
CONTENT
ssdeep
|
24576:yB4M4C3wITXhGdCkpDLPC+hMpYjQPKA9yZ6d:yB4M4C3wITXhGdCkpDLPC+hMpYjQPKA3 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
abf3d00c6933b661 |
|
VISUAL
aHash
|
ffffef01011f6f7f |
|
VISUAL
dHash
|
c4db4873332c8bda |
|
VISUAL
wHash
|
03ffa701010f4f6f |
|
VISUAL
colorHash
|
01e00000000 |
|
VISUAL
cropResistant
|
c4db4873332c8bda,71c0b2c098da7831,71c0b2d6d6a0c470,699934564a48c9f1,c9cb4b59dbababa9,5056a6a6a6aa6a6a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain