Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15641C475E89218267C3BC671E8D9891526224D9ED2A202F38AE1012FA2D4D6DDCC71BC |
|
CONTENT
ssdeep
|
48:1AVVd6jPJYoD/k6jPBrRV9FP1A2AFP5fJtWtFP8yjNfAzvFJu:K09TBn9YLfqtdNAu |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9d9e0e41e34c9e1b |
|
VISUAL
aHash
|
1f0f0f87ef080003 |
|
VISUAL
dHash
|
7cfe3e1edad2d34f |
|
VISUAL
wHash
|
1f1f1fcfef080803 |
|
VISUAL
colorHash
|
07001018080 |
|
VISUAL
cropResistant
|
7cfe3e1edad2d34f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 82 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 1 other scan for this domain