Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T108731AE87D0EE4275EB383D610DB04477269611B904C4CB06184EDA97BFCCAA616BFDB |
|
CONTENT
ssdeep
|
768:0lROc8OszbL0tVF17XAIA7qLKE0pGcrTALCrJAixaFbfllCGOKGxd9i3fZ+8Yl5e:AmohVj0jhJPYbfl4GTGli3fZFc+gw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ecc736cd9419c932 |
|
VISUAL
aHash
|
f3e1f1ffffd18187 |
|
VISUAL
dHash
|
270f03130e332b2f |
|
VISUAL
wHash
|
f1e1e1e3ff818181 |
|
VISUAL
colorHash
|
07000040007 |
|
VISUAL
cropResistant
|
270f03130e332b2f,274b942c1c0d0d19,a8b00c4060000408,08a93084c0108060,0190468989669091,909947a4840ba0a0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 18 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain