Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T195F3DAA0D0106A3B14A3C2F6D7B1AF96B39AC38ACBC15296D9F5C36F47D2C90DE13558 |
|
CONTENT
ssdeep
|
3072:DOjwr4kbtpSbtvir45btpWbtGz4Id3mF4IR3q4IY3m4IT3T2vaxNPTBNR5vbnD3j:DO54Id384IR3q4IY3m4IT3T2kNPTBNRR |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8acb353574562e5c |
|
VISUAL
aHash
|
077b797939090101 |
|
VISUAL
dHash
|
fefbf1e1b3f3f9ab |
|
VISUAL
wHash
|
1f7f7979391b0101 |
|
VISUAL
colorHash
|
06e00000002 |
|
VISUAL
cropResistant
|
e77f1e1e2e5e3af6,f6fefcfcfcf8f8f0,fcfcfcfcfcf8f8fc,ae3452cbefcacace,c480e05a51cc80c4,fefbf1e1b3f3f9ab |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain