Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D00432B2D8623133212F25C6F17DAB5DB4D3E70EEA8357C182E843686BD5C95B837528 |
|
CONTENT
ssdeep
|
3072:ofIw1u+pVNFbnnHXNN5NlNrnv/RBXF7fNl9pJlbd/3Fjt5NT/XIW7iwz7iGIW7im:ofIw1uW/XIW7iwz7iGIW7ifyAGwGR2RQ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8a5f17555507574a |
|
VISUAL
aHash
|
00ff35ffd1ff7fff |
|
VISUAL
dHash
|
d0ad6da6a51de2c6 |
|
VISUAL
wHash
|
00fd01f740ef7f42 |
|
VISUAL
colorHash
|
07003008000 |
|
VISUAL
cropResistant
|
8080c2d2d2828080,926d65a7a55de28a,d0d8e8d8c00aa22a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2600 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 10 other scans for this domain