Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12AD2A4A05600583785A387E5FB7BAF1B62A1C346D703018381F8D76E9FE6CD0DE56E68 |
|
CONTENT
ssdeep
|
384:0PMOSnRsIoQfWpXkOHWmbp8OasdvFHVjAhmmdFuLQ1PxwJVz:7ni3elmbp8OasnVQmmOLuxwJVz |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fcf44343d23838ab |
|
VISUAL
aHash
|
3cffdfffff0000ff |
|
VISUAL
dHash
|
dc0637b400f06300 |
|
VISUAL
wHash
|
00f3d3d3ff0000ff |
|
VISUAL
colorHash
|
06000000007 |
|
VISUAL
cropResistant
|
508027b6b4041004,6063134000000000,0100030b0b0b0001,004000f2d0050000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
| ID | Português | Inglês | Trigger |
|---|---|---|---|
Found 2 other scans for this domain