Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1301211305484A8674103A2D6FE299A1E3DD5827FEF934B0152F80B9EA6F2C64CE3F355 |
|
CONTENT
ssdeep
|
96:AnscN24yGGOZ/NROcMCxjAmxpJcVAfk+GOZjoNWDwiNmLMrH/p/iGOZ1aYVvGvtq:I2zGb61AdhcVA8+bjoKH9/ibJVP |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ac6c139b2d662e3c |
|
VISUAL
aHash
|
01ff93d3d3ffff3e |
|
VISUAL
dHash
|
7f3226263632e8e8 |
|
VISUAL
wHash
|
00ff938383ff7e00 |
|
VISUAL
colorHash
|
06e00000040 |
|
VISUAL
cropResistant
|
7f3226263632e8e8,3e6d6d7564ecdd0e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 55 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain