Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F13308206211B36E6D334F78F38934B6D1AED384E5E6682DB3A5829131D3178CB5BCE5 |
|
CONTENT
ssdeep
|
1536:kmY1wA38nX+2ANTdI0ff3E4trYeSKq8Z7U1c/jDEtYJ72fkOekEbQSFenh1fn:c1UtYJ7M |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b332cccc3333ccc6 |
|
VISUAL
aHash
|
efffc7c7c7ffefff |
|
VISUAL
dHash
|
1d160c8d8d1e1e5c |
|
VISUAL
wHash
|
8183c7c7c7c3c387 |
|
VISUAL
colorHash
|
07006000000 |
|
VISUAL
cropResistant
|
1d160c8d8d1e1e5c,96f979f47833e4f4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 394 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 5 other scans for this domain