Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C7C1403090586C3713A399EAB6BA6B1BB6C9C659CB174F0563F8439D2FC7C25CE56320 |
|
CONTENT
ssdeep
|
96:PY1uo15g8GI3kFehw6LM4S+LrEVdkB2oxCi6KmBS+Th2WlFxr3IWdcqH3H0oTmoT:PXojg8GI3kFehbei2oxCTKmB9X7M+fs4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
98c936e398c99ce3 |
|
VISUAL
aHash
|
ff00181818180000 |
|
VISUAL
dHash
|
900cb2b2b2b28304 |
|
VISUAL
wHash
|
ffffffb818180000 |
|
VISUAL
colorHash
|
01000000007 |
|
VISUAL
cropResistant
|
000080a0a0000000,a2a2c2c4e08686b2,0c32b2b2b2b20e14 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 39 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 7 other scans for this domain