Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13FB392D61628438CA14B996DEF2FFE05131FB0AAB95889801A4FC26CD2DF4D6F71752C |
|
CONTENT
ssdeep
|
768:kn5Nlz73u1rRf6hxG7krl0RQ7H7Z/9PyfR8MRERXQHK51qRXoCX/9PyfR8MRERXr:85jj0RQ7H7ZFsR8MLqc3XFsR8MLqceWA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
af6fc1c490909e9e |
|
VISUAL
aHash
|
ff8181818183ffff |
|
VISUAL
dHash
|
2b2b2b3b332b9c16 |
|
VISUAL
wHash
|
fb8181818181efff |
|
VISUAL
colorHash
|
06e00000000 |
|
VISUAL
cropResistant
|
2b2b2b3b332b9c16,c9c9c9cd79f5e0ca |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 150 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 1 other scan for this domain