Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T116047777D168140B1347A7FC22547BDDA3D7524DF68B8900B2AC82CB7B94C53ACAAE35 |
|
CONTENT
ssdeep
|
3072:NwfzIfnDr7Tzqgozr7Tzopr7TzKY1FNtTjNU:NwfzuDr7Tzqgozr7Tzopr7TzKY1FNtTm |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cba698e32c39939c |
|
VISUAL
aHash
|
ffff7e0000241818 |
|
VISUAL
dHash
|
f1e0e8076949f2b2 |
|
VISUAL
wHash
|
ffffff00203c0818 |
|
VISUAL
colorHash
|
18007000000 |
|
VISUAL
cropResistant
|
5652bacccc295252,1a9ad49595d4aa2a,60e000a4636300a2,f1e0e8076949f2b2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 75 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 7 other scans for this domain