Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B752A364230C192D601747C4FFA5F779639EA396E31D501CE0AE22629783DD5ECB3AB8 |
|
CONTENT
ssdeep
|
96:R39GS27MrS2eSTuliZqj1ufcya/koXLk77mbukPVieu7mbp5Vi77mbAfViq7mbOc:FNbW8+iZqUUN7+ciMihiai8pFF6/5pHT |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8cccad3333332766 |
|
VISUAL
aHash
|
8018381800000081 |
|
VISUAL
dHash
|
13b0213101110013 |
|
VISUAL
wHash
|
813cff000cff00ff |
|
VISUAL
colorHash
|
38007000000 |
|
VISUAL
cropResistant
|
13b0213101110013 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 715 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain