Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BD43B7735108AA3F0691B2D8B558FB08D653C28ECE6166CFABFC42489787E71D73691C |
|
CONTENT
ssdeep
|
1536:W4fJNuyV9YeaYe3c7dnYl1Qw024imUo6xuOCgROpdaxS9:W4fJNuTQ9 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9545ea02f83ce9ea |
|
VISUAL
aHash
|
3a3e3e1e1c3e1fdf |
|
VISUAL
dHash
|
f2caf0f4f0f0b139 |
|
VISUAL
wHash
|
183a1e1e1c1e1ddf |
|
VISUAL
colorHash
|
06e00000001 |
|
VISUAL
cropResistant
|
f2caf0f4f0f0b139,e8edf5f4fad4fef8,0e07323133075140,526469612c266662,234be92c35e3c64f,3465890d190f67e7,67e3c7cdcbdb9e9f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 54 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 3 other scans for this domain