Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1ABB2823161227A3303479AD4B9657B5E32E7829DC807241143FEA3E42FFBD94F86B619 |
|
CONTENT
ssdeep
|
768:hKithk9gjdQ/lQORgD4L0nrje6j8s4IieVlS:fthk9gjdQ/lQORgD4L0nrjjj8s4VeVlS |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ad436c59d6f8d812 |
|
VISUAL
aHash
|
000001ffffcbc3c3 |
|
VISUAL
dHash
|
cbc3d32027132b2f |
|
VISUAL
wHash
|
000053ffffc3c3c3 |
|
VISUAL
colorHash
|
07002000180 |
|
VISUAL
cropResistant
|
3938363713132f2f,808bcbc6c2c3c3c3,0c12323212120c10,909999cbc6c6d2c6 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 165 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 10 other scans for this domain