Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A33395F2129006EF64D386F06E71172E6257B3A2EA4791CA76B8C31B7EC7DB0CC52651 |
|
CONTENT
ssdeep
|
768:DALgecFZELk+Cu6hUgxqnidzJtJweImHkIfU7ME9AogWfP1+Np:WgecL+CKnj2p |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c46ec09c6a5f946e |
|
VISUAL
aHash
|
18000000007e7e7e |
|
VISUAL
dHash
|
3070102192969696 |
|
VISUAL
wHash
|
181800005affffff |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
3070102192969696 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 1 other scan for this domain