Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C3722230614C9D39998386E0F3793735A1A3D2CFDA4F0254D3E49779AAA6CC6FC62264 |
|
CONTENT
ssdeep
|
192:DY7/7Q6S31baU+fDXF1cs96Uwfe6z6k656h6P6J6V6Zs6V6G6q6v6Gb:E7/7Q6SLCXLnUUwE |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d9e693e698262699 |
|
VISUAL
aHash
|
fffef8f818181818 |
|
VISUAL
dHash
|
0808103032303232 |
|
VISUAL
wHash
|
fffef8d818181818 |
|
VISUAL
colorHash
|
01c00018000 |
|
VISUAL
cropResistant
|
0008101030323230,969ecabadab2ba8a,cad392add355159a,1030323230323232 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain