Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12FB1C62FF00D3B394683038BB5E82AEAB62B506D5361579D6DE9811C77E17D6C1372C1 |
|
CONTENT
ssdeep
|
96:TTvC99/dAeA8vKsxnjUB+5EDaP0iYxoXDJ6sC0ImECOrwvno6pcuXr:3+xdvsVQSo0nxo6AIPkn |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b81871ce63ce694e |
|
VISUAL
aHash
|
b98f8fdfdfffffc7 |
|
VISUAL
dHash
|
3b1c3a303dc0e45c |
|
VISUAL
wHash
|
38080c1e85f3ffc7 |
|
VISUAL
colorHash
|
07008000c00 |
|
VISUAL
cropResistant
|
3b1c3a303dc0e45c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 3 other scans for this domain