Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F362A6B0A0156AAB43478AE8D121671F3197D357CA4F3C61FBE453EE2AE9CE4EC18845 |
|
CONTENT
ssdeep
|
192:BXJQ6JPOqm+8m//fxHOEk+gY0pLlz+63jPUzOO6Vi45SsDUgd:B5vJm9gHxdk+yLjTUqOoHYq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b9c6c66731330ec6 |
|
VISUAL
aHash
|
ffff9f8f8f898f8f |
|
VISUAL
dHash
|
30023b5b193b1b1c |
|
VISUAL
wHash
|
ffff898980818707 |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
30023b5b193b1b1c,9ab8dd4c3c28b194,9e0f09636f0c2d38 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 2 other scans for this domain