Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D84274336040C12E4E9742ECFAD8BB9AA14DD245F73089866AF4507FAB80DEC653575E |
|
CONTENT
ssdeep
|
384:rgq7m84xP01qMKJJ8vZAMeKmS1k7u1eUfMmUFCoR:rlm84h01qMKJJ8vZA2mS1ky1eUfBUsA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
91959195bd65ea46 |
|
VISUAL
aHash
|
7e3e70000000001d |
|
VISUAL
dHash
|
dad8c89088d1886d |
|
VISUAL
wHash
|
7e6e7e40484068ff |
|
VISUAL
colorHash
|
38c00000000 |
|
VISUAL
cropResistant
|
f1f9f1f2e5e6e4c9,38383cbc3c983bc9,650d057173010c00,dad8c89088d18865 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain