Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T101841BAC120116BEB05B87E5FA20F3DE616FD29DDE93C90DF3AC82962BC1C98CD54594 |
|
CONTENT
ssdeep
|
3072:eE0cPP+5DPtVbFl5dD3e3GVVPqqPlq20A:RDIXw20A |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8bcec47a7a846a99 |
|
VISUAL
aHash
|
803f3f000d007f0b |
|
VISUAL
dHash
|
4b69f0d35b5bfad2 |
|
VISUAL
wHash
|
b07f7f000d007f1f |
|
VISUAL
colorHash
|
180030000c0 |
|
VISUAL
cropResistant
|
972a8f51fbcfd757,73cde64aecececec,9294aca434939292,4e5753376ecee2e2,2733194c84e0e260,65cd2d2dcf666466,8e9c1694ac96d461,4b69f0d35b5bfad2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 36 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 1 other scan for this domain