Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T162B2A8F4A055AC31A2A3CDCF6B605B596593E247DA234E86C5E4C36827C6ED7FF23108 |
|
CONTENT
ssdeep
|
384:pQQj+Y/902042+G8/3JiuC6rNbPuDiev+WEuDSw+ogqa1KF:pQQR/90B4+8/3R3xKDND+ogq4KF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ce3364313333317d |
|
VISUAL
aHash
|
00383c3c3c3c3838 |
|
VISUAL
dHash
|
6961616961616161 |
|
VISUAL
wHash
|
3c3c3c3c3c3c3c3c |
|
VISUAL
colorHash
|
39032000000 |
|
VISUAL
cropResistant
|
e21842a238fa6272,c9b9b9d827251d33,6961616961616161 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 23 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain