Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T174B20DB110A07827520359E0F1E1E7DF7E9293CDC546EB01E2B586A84FE8C6EDC564AF |
|
CONTENT
ssdeep
|
192:Q+vp5oxIE8SVw0o9FaHnzrwpEcVvioxIEihSVw0IFaHnzrwpEcvuoxgA0lPhUSiU:QIpeIEupZPIEapvDgAJ1w |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92936d6c6d9364a6 |
|
VISUAL
aHash
|
000c0e0e0e0e0c00 |
|
VISUAL
dHash
|
275858585c545826 |
|
VISUAL
wHash
|
0e0e0e4e7e0e0e82 |
|
VISUAL
colorHash
|
07006000000 |
|
VISUAL
cropResistant
|
a2a080808e3236c8,275858585c545826,01208c6961680400 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 15 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 5 other scans for this domain