Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11D02A860AA9940BB365781EFF0715FB8EAE99C4EC613AD89F3B856C1C781D044E17D60 |
|
CONTENT
ssdeep
|
96:Tk9MQ+St3jJDO8ZDJ18oxmocH/OfqXPXmRw3ZEU6+hEelCwitOZD2w1ctqtnD6JY:YMdStFD5qZ7T+OJtnD6EtmUhjPKE |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bb59d56c082ed14b |
|
VISUAL
aHash
|
084c7f1901ff07ff |
|
VISUAL
dHash
|
b0d8d931334d6dcd |
|
VISUAL
wHash
|
00487f1901ff07ff |
|
VISUAL
colorHash
|
06600008000 |
|
VISUAL
cropResistant
|
b0d8d931334d6dcc,0000606060800000,0c90f0b0b0f0918c,2f775f041b397d39,9c97332dad492b0e,4699796931230703,7169b5b6974d6131,e3d9e7e5b1323131,1f3b7535bcb6b465 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 42 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 2 other scans for this domain