Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19C9354607953683620AF51CFC22B071D72C1DBC9EA5367E951F0C3685AFAC90BFE61A4 |
|
CONTENT
ssdeep
|
1536:XBG7O6rpswrJ4ZOP8jlcxglJuGJTnJJUJiI/dVATGTDF5bTJjcTXu/sF:X6wOPO+onUUI/dVAd |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
88dd2275aa37899d |
|
VISUAL
aHash
|
1d383c183c180009 |
|
VISUAL
dHash
|
71f07070703254f1 |
|
VISUAL
wHash
|
7f3c3c3c3c18183d |
|
VISUAL
colorHash
|
38000c00000 |
|
VISUAL
cropResistant
|
71f07070703254f1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 53 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain