Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B3D2F832E0284C27784B87C8E754EB0A63C6920DCF4209D9D3FDC16BA7E7D7AAD11995 |
|
CONTENT
ssdeep
|
768:TRjEdXjDHEyw2IcqpXo9Vn4Vjt8KJFmVFCAWxQyoZZmItyfChd4jW4cNjoMyLYHD:djEdXjDHEyw2IcqpXo9Vn4Vjt8KJFmVj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ecc6929b199b6c2c |
|
VISUAL
aHash
|
fff3f1f1f1f3c3c3 |
|
VISUAL
dHash
|
3927272327270f2b |
|
VISUAL
wHash
|
81f1f1f1f1f18381 |
|
VISUAL
colorHash
|
06201008080 |
|
VISUAL
cropResistant
|
3927272327270f2b,e7cfaf8e591f0b6b,c66626cf4b19938b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 641 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain