Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19C92B6379340A73D4A2603DDAE6B379EB3B2404DF69A05D4E1FFC23E5581CA0993AC95 |
|
CONTENT
ssdeep
|
384:0BnE93lKOA/rkfAV4t9uRWndtzhSD9jAmfCG:0BEhokVeytCA8t |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b04acacacaceca9b |
|
VISUAL
aHash
|
fdc7c7c3c7c3c7c7 |
|
VISUAL
dHash
|
491c1d0e1e161e1c |
|
VISUAL
wHash
|
a5c3c3c3c3c3c3c3 |
|
VISUAL
colorHash
|
07000000007 |
|
VISUAL
cropResistant
|
491c1d0e1e161e1c |
The phishing kit employs a credential harvester to capture user input from form fields in real-time. Data is likely exfiltrated via HTTP POST requests to a command-and-control server upon submission.
The kit includes modules for intercepting one-time passwords (OTPs) and credit card details, possibly through fake authentication prompts or overlay forms that mimic legitimate services.
Minified JavaScript file with potential credential harvesting and card data interception functionality.
Found 10 other scans for this domain