Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D2C18629735146BECD074BE1BB20957C6047C38BD0F5662CE7B800B0A386CEDE4E56E9 |
|
CONTENT
ssdeep
|
48:Txv15nZIUQPrN2DfwkJ1QbXoGjdRZ2DfwkJ1QbXoGjdRazj6ceUmGOzUbaYnwGN7:ThnZnQDKww1wz3eww1wz3CWK3bdnHDrz |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8b0383870f2f2fd5 |
|
VISUAL
aHash
|
7fff0000ffffff00 |
|
VISUAL
dHash
|
d100d11100110011 |
|
VISUAL
wHash
|
3f030000ffffff00 |
|
VISUAL
colorHash
|
07000038000 |
|
VISUAL
cropResistant
|
d100d11100110011,0000303131300000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 2 other scans for this domain