Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DFE222709116AA3B02F3A2E17BB46B5FB3C9E2C9D902470516FC975D8FCFE84E921151 |
|
CONTENT
ssdeep
|
384:PEVGRc+VGfoB5+6BoWCygUyD084mR8m9nVlmovK:PE0c+VCoB5XBoZ1WQ8y2ovK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9393537e3e654185 |
|
VISUAL
aHash
|
ffff7f9fff000000 |
|
VISUAL
dHash
|
4d28d03928c06161 |
|
VISUAL
wHash
|
ffff7f05bf000000 |
|
VISUAL
colorHash
|
03001000380 |
|
VISUAL
cropResistant
|
0c000808c0e2f8fc,f1b1b163746c31a0,24d0c0b2b280d201,4d28d03928c06161 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 54 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 8 other scans for this domain