Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10322507092A6792302A382C1AB766B5B73E18248D7530B0563FCC36EAFCAC96DD175C5 |
|
CONTENT
ssdeep
|
192:QZfPSQDXr0UQuJvzuEeVu+OiHRW7vPqw5aXg2:GfDDNpK3VRT+Hqw5aD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ca90b56bd7947289 |
|
VISUAL
aHash
|
c1f7febe3880dbfe |
|
VISUAL
dHash
|
13ab4d61490533a8 |
|
VISUAL
wHash
|
81c3fcbc38009bfe |
|
VISUAL
colorHash
|
07001038000 |
|
VISUAL
cropResistant
|
13ab4d61490533a8,232b2bd4d4d4544c,2b2313276e6e2713,b200686c0230344e,1f3e3f7b333b9ef3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 24 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 1 other scan for this domain