Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17FF165B031215FBB5167C5F0B6C1AB4B51D5F35ACAA3490053F8836A3BCBDE4DE26221 |
|
CONTENT
ssdeep
|
96:gyOhwuipaYzh69YF7+CkVd5Bz3XY7qfxzrhD3WXEwXWXFJKVj6bhWSf:x86pDhbihnhfVrhLtcVGbhlf |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b173ce8c1058dfb1 |
|
VISUAL
aHash
|
ffefcd484f7fffff |
|
VISUAL
dHash
|
809b99999999860e |
|
VISUAL
wHash
|
7fc9c840406f7bc3 |
|
VISUAL
colorHash
|
07202000080 |
|
VISUAL
cropResistant
|
809b99999999860e,001020b2b2320800 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 65 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 10 other scans for this domain