Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DFF210709115AA3B02F3A2E16BB47B6FB3C9E2C9D903470426F8D35D8FDAE94ED21151 |
|
CONTENT
ssdeep
|
384:PEVqRc+VGboB5EbtWNvnLmoWCygUyD084mR8m9nVlmovK:PEAc+VqoB5QcNvnLmoZ1WQ8y2ovK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
83f29e736b0ec18c |
|
VISUAL
aHash
|
24ff7e00407e1c1c |
|
VISUAL
dHash
|
4d28d49393d428e8 |
|
VISUAL
wHash
|
24ff7e00417e1e3c |
|
VISUAL
colorHash
|
000000003c0 |
|
VISUAL
cropResistant
|
0c000808c0e2f8fc,24d0c0b2b280d201,d8cc8f29b3bbc9c9,91789a831533b2ae,71e8cc9c3b8f2c27,dc989b9e951fa386,4d28d49393d428e8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 54 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 8 other scans for this domain