Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FE24BC23461879260537C2C530BA4B37D29ADE5FFAA70A414EDCD7F72BEACA0715B049 |
|
CONTENT
ssdeep
|
1536:rLoKSg5AUMZ8wwkI/mpP5XrhA7aXfGTJnZRTksPSGIhIEBa4QuoB1tGYUP+IfNvm:QdvOblBa78Anu |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
968d1c872e871b97 |
|
VISUAL
aHash
|
0000ffffffffff00 |
|
VISUAL
dHash
|
61b45d4d4d4d4d39 |
|
VISUAL
wHash
|
00dbffe7e4e47400 |
|
VISUAL
colorHash
|
07000008038 |
|
VISUAL
cropResistant
|
0040606868616162,b65d5d4d4d4d4c39,e4e6e6e6e6e6e0e6,6060a0a084846060 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 26262 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 5 other scans for this domain