Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B614973BC068151B1207AAF863947FDDA3DB514DFBD74800B1BC868B67D4C92AC6AE35 |
|
CONTENT
ssdeep
|
1536:YGFgqqHo6wwUBbXhOXMNKdwMUr9r/mnpHxozTFgaOVpMnbZTFgO4Zj5oqTFgGQ1f:8vz/BUmp7LI |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e869c795941e9279 |
|
VISUAL
aHash
|
ffc18181dbffc3e7 |
|
VISUAL
dHash
|
de032b3796c80f4d |
|
VISUAL
wHash
|
7e818181c3ff81e7 |
|
VISUAL
colorHash
|
06002400048 |
|
VISUAL
cropResistant
|
de032b3796c80f4d,fcece6a6d656ae5e,6555983090d81c5a,981ccdcf4c4e464c,0f34b43c5d130306,63e7c91b7edcdb74,6e46291d65251945 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 72 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 9 other scans for this domain