Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FF6331B37170ED3F00538BE4B667571E6292A269C9C602C217F8B79B1BE6C50ED27E05 |
|
CONTENT
ssdeep
|
768:ND3QHMC4lI8kMz26GZZD3QHMafA7A7777GHMII3GuZJuZ6VW6KO/:9xlItMz26GZhPA7777G6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
becbc13434c586cd |
|
VISUAL
aHash
|
fff9fd878387ffff |
|
VISUAL
dHash
|
1b2b612e3f3f3353 |
|
VISUAL
wHash
|
fd819983838383fb |
|
VISUAL
colorHash
|
07600008001 |
|
VISUAL
cropResistant
|
1b2b612e3f3f3353,c9c9dbdbdbdbdb6c,6f7b1ae8cca9d9c4,7b743e37353105c4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain