Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17142112B7304A7260F7301C5A7C1A2D99376F285E3710DC1E18981AEEBDADF67171B68 |
|
CONTENT
ssdeep
|
192:8UpYlPdkR2a+yXy7bcU3aF2dQtZhYTKbyVyj7tqKTcfuuSqwF+cSXpGq3fAPAcpm:8mYlP5yINY/C2IwcGPAAK4BfMmUFCoJx |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9111f2e616369d6d |
|
VISUAL
aHash
|
0400000000ffffff |
|
VISUAL
dHash
|
8c9a9a1c22003f3e |
|
VISUAL
wHash
|
060e0c0400ffffff |
|
VISUAL
colorHash
|
1e601000080 |
|
VISUAL
cropResistant
|
fca4a4b2f2d2c7c3,0000000000010400,60c4c4a480828280,000004181f2f3230,fc889aba98dc1c80 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain