Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T195921853CC25614FB12542D0B44E3B5499CADD3F86F28E98E4FBE3D0AB758A0D729264 |
|
CONTENT
ssdeep
|
96:TGUFXgQG1fU1lYxlnl6lxlel4SlFlkl0llgl2l6lQlVlylHlnlLl2lMWEbWEYrWv:aU9gFWaEz9NxtVa1s9H3ou7PPWkKkog |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fbe09b5e08a5bd02 |
|
VISUAL
aHash
|
ffffffe3008c8c00 |
|
VISUAL
dHash
|
a0ca5ed6103a581a |
|
VISUAL
wHash
|
ffffffe300888000 |
|
VISUAL
colorHash
|
13600008000 |
|
VISUAL
cropResistant
|
80e0c84aced216d6,379dccd4ecc4a43c,b1b3b268e8391030,ecec6b3996909493,ce56d6d53818581a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 1 other scan for this domain