Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13A234B72A332B87843DB92EEE7383955B2D2589DE8C74554F1C596CD23C3C806297BB4 |
|
CONTENT
ssdeep
|
768:aE+EsZx8/G8r2vDVScMDBGSUMDB0Ucix+y9dQpUDF1E56ITmHTCd3m6DPqDv7A1+:aE+EsZ/8rsDVScMDBGSUMDB0UXx+y9db |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bb956ac495c5d491 |
|
VISUAL
aHash
|
ff818f8f8f818181 |
|
VISUAL
dHash
|
43095b5b5b594509 |
|
VISUAL
wHash
|
ff81af8f8f818181 |
|
VISUAL
colorHash
|
33c00600000 |
|
VISUAL
cropResistant
|
43095b5b5b594509,fef9f1a1b1a2e4e1,343038383cbc9c89,219a9a9adaca8aa8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 17 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 2 other scans for this domain