Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13D521F319466B97302C392E1AF3653AFF3E28284CA130B4192F5C38DAFDAD46DE13549 |
|
CONTENT
ssdeep
|
384:5KrEsh9t2IIeQuIUvH8agu8S1I/m7hiIKM0w7:5KrEM72VFUH/gWa/mpKRw7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9ccc766631939ccc |
|
VISUAL
aHash
|
06103c1c18180404 |
|
VISUAL
dHash
|
cc25317233724c1c |
|
VISUAL
wHash
|
e797bd1f1918240e |
|
VISUAL
colorHash
|
38e00010000 |
|
VISUAL
cropResistant
|
82848c289ad25abc,c4b5b9d555315149,cc25317233724c1c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 12 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain