Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10E235A726332B4A843DB91DEF7382946B2D2988DF8CB8554F5C95ACD13C3C942297BB4 |
|
CONTENT
ssdeep
|
768:aK+EsZx8/G8hH4hDawRMvBlw7MvBQwZqN2/y9dGDTDiJE56ITmH+LCBlvNPqDvK/:aK+EsZ/8hYhDawRMvBlw7MvBQw0N2/y5 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ee99b2c7a1c48cf0 |
|
VISUAL
aHash
|
8181999981998181 |
|
VISUAL
dHash
|
2b31717171716565 |
|
VISUAL
wHash
|
ff99999991b98181 |
|
VISUAL
colorHash
|
3a2020000c0 |
|
VISUAL
cropResistant
|
2b31717171716565,f1880c0c0c8c9ad2,a082c272727282a0,6a70b2f0f070aea0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 17 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 1 other scan for this domain