Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T162A1DB30906DDC6B514B81D5B270AF0E37E1D281CB634B0423F8A7AD6FDACA6ED56294 |
|
CONTENT
ssdeep
|
48:T7YCm6R5kCKy7H3eYOBRU5COEB12YBRRCOQeBTm/5BRMiODB5+RBth30h6YqC5QS:TrmGkCdXb/0DX+R7h30WC5Qk+Mf |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f676c9c9349c8989 |
|
VISUAL
aHash
|
e7c3c3c3c7ffffff |
|
VISUAL
dHash
|
8c0d0c0c4c400400 |
|
VISUAL
wHash
|
4280808282ffffff |
|
VISUAL
colorHash
|
07000010180 |
|
VISUAL
cropResistant
|
8c0d0c0c4c400400,5055f0e4a6a6e069 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 212 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain