Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T171731D72DC601437116B62CBF978EB5E71E3C38BEB43268156F843946BE2D44992BC39 |
|
CONTENT
ssdeep
|
768:hXCixR3ljRG3EQRG3zaRG32aRG3Fzcp4YaLWHwH8miEwpICfOH/exyUGajeL:hyo4YaLWQHlYM/esaj4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8787474343d75353 |
|
VISUAL
aHash
|
3cffffff00000000 |
|
VISUAL
dHash
|
e8266060d0f1e424 |
|
VISUAL
wHash
|
ffffffff00000000 |
|
VISUAL
colorHash
|
03007000000 |
|
VISUAL
cropResistant
|
8080c2d2d2828080,4a41624150603001,d0d8e8d8c00a931b,12e8e4d0e4e42422 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2581 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 3 other scans for this domain