Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1617354343901682630EF86CEE263794E2284DFC6C9571AD9C6F1476869F7C61FED12D8 |
|
CONTENT
ssdeep
|
384:YWH+sptrDQ/gTqrZBSwFVZ4zj6P4RU46zg4z01Zt4nR4oWvZkZwFx:IcM3tax |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f15c59620f97136c |
|
VISUAL
aHash
|
20c0c60771e5c74d |
|
VISUAL
dHash
|
4d12186ec79d9b99 |
|
VISUAL
wHash
|
20c0cf07f1cdcbcd |
|
VISUAL
colorHash
|
07000038000 |
|
VISUAL
cropResistant
|
4d12186ec79d9b99,3636f37252ea9692,c180888390f2706e,000040d0d0c04840,4b94b6f6e6c4d42b,2dbcb4343c94d429,a241a6aa98bab21c,8e335979e0c4cccc,386f6373b3eb7357 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 503 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 1 other scan for this domain