Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T194D194B15049D836A0E381EDE8A0136F7580030ED75386C6F7FA03AE9BCADA4DF65295 |
|
CONTENT
ssdeep
|
192:mGqYlfH6ghYPsOl/sOQVcsOq444ptLuwoNe:m4xaLEOl0OQVzOq444v |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9bc819b5bb2ac90d |
|
VISUAL
aHash
|
5c3c383d3f26060c |
|
VISUAL
dHash
|
d1f1f359724e5438 |
|
VISUAL
wHash
|
3e3c383d3f3e040e |
|
VISUAL
colorHash
|
38000000602 |
|
VISUAL
cropResistant
|
c4c76331b85c2ef6,b233754345f4a3e2,9391c8c466b1188e,4444588060706480,9be234997ab66c8b,08c63399e47a9d6e,d1f1f359724e5438,16cc59b264cc9a32 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 154 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 10 other scans for this domain