Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D9414479304256FF068B4DE8F1E8EF25E0CFD70AC623C49856AD81E93BD4D806E14A40 |
|
CONTENT
ssdeep
|
48:TRPe8WCjnDtQA4CQ6eAVP3VXiMabx9rbJ2p3gtWSbUkIQ:TRPe8WCjDtQA4P6ejMYkxSbUkj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8a0085d13f7f1fd1 |
|
VISUAL
aHash
|
ffff0000ffffffff |
|
VISUAL
dHash
|
80c4915500000060 |
|
VISUAL
wHash
|
18000000ffffff3f |
|
VISUAL
colorHash
|
07009000480 |
|
VISUAL
cropResistant
|
80c4915500000060,0008303232100800 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 2 other scans for this domain