Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T152927470A4854B7B218346D1D3B9BB25B2D1A1C5DA820FCADAF4578BCFAFF91CD02485 |
|
CONTENT
ssdeep
|
384:wU0M0ZfF6LLEvzsyn5xq1sH8sFU/cqAOBTxkfXnUO6:whJZfSEvz73T1U0qFxxEK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9212ecec19c5ecec |
|
VISUAL
aHash
|
2e0c0c0c0cffffff |
|
VISUAL
dHash
|
d899f8d859455929 |
|
VISUAL
wHash
|
0c04040c0cffffff |
|
VISUAL
colorHash
|
07c00008000 |
|
VISUAL
cropResistant
|
d899f8d859455929,71626c6673f5f7cf,101c3c5850204040 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3471 techniques to evade detection by security scanners and make reverse engineering more difficult.
| ID | Portugués | Inglés | Trigger |
|---|---|---|---|
Pages with identical visual appearance (based on perceptual hash)
Found 3 other scans for this domain