Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CC334A73A365787D83DB82DDB7392F41B6C6A48DE9870450B1D8A6ED23C3CC26287764 |
|
CONTENT
ssdeep
|
1536:a3+EsZ/8legOvDT1eJSdMDBWSMMDBEUXx+y9dQyDF1M3m6/P3ySu:ao4S/SqUXxpDzHzSu |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9818f3e5cec2e12d |
|
VISUAL
aHash
|
ff00000000e2ffff |
|
VISUAL
dHash
|
80bcbbf136d60092 |
|
VISUAL
wHash
|
ff00080800faffff |
|
VISUAL
colorHash
|
0fe00008000 |
|
VISUAL
cropResistant
|
880c80c800a888b4,636ac6d6e4bcf97b,bca89451a1a97672,3656d60802000000,bc37bab0713136d6 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 17 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 3 other scans for this domain