Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16A731AE83919F5261AB343A710EF14037378121B640D4C70B295FD9EB6B8C5AB16BFE9 |
|
CONTENT
ssdeep
|
1536:uT6cRwMjQC7JeDEzh9yRjGQlUuRNka2wblHbJLwLIz9GguGOjjRnY:5rX2wd9W/guGO+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ce9c93a6cc8ca3a6 |
|
VISUAL
aHash
|
ff0d0d1980a0f0f0 |
|
VISUAL
dHash
|
7d795555554d4141 |
|
VISUAL
wHash
|
ff0f079981e0f0f0 |
|
VISUAL
colorHash
|
18007000000 |
|
VISUAL
cropResistant
|
7d795555554d4141,fcf8d4d4d44cc0c0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 1 other scan for this domain