Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BCA2677252620137063B4ED671BD636BA3F1E38EEB47046482ED436C07DFD92B667226 |
|
CONTENT
ssdeep
|
384:+MhTtFugSgsgvgjwg+g2rd67qmRaxi5lhfNa3/E8Z58p9t9y5iWrIMKiJrIu8iYW:+MhTup1iEw/rd67qxxi5P1Y/1Z5e9tMd |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d678173d28ab2935 |
|
VISUAL
aHash
|
0c3c7c7c3c3c3c3c |
|
VISUAL
dHash
|
58d4d4dddcdcdccc |
|
VISUAL
wHash
|
0c3c7c7c3c3c3c3c |
|
VISUAL
colorHash
|
06e00000000 |
|
VISUAL
cropResistant
|
fcfcfedeceeacc1c,f0b4b4b4bcb09cd4,eede38f0c8f0f84d,0ed949818ce6f333,b7b76dad343731b8,231b0f0e03252726 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 26 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 10 other scans for this domain