Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B9E272AE96547C3B019347D3F93C571296E5CA47DA871958B6FC839C0BC2DB0EA7202E |
|
CONTENT
ssdeep
|
768:OoKX9lx92Caixmw5yQfC0sk2pRt5nXxXXLlXpuvuQyZmdW:5Caixmw5yQfC0sRpRt5nXxXJXpuvuQyD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b4cb3418cb34cbcb |
|
VISUAL
aHash
|
ffffffffff878383 |
|
VISUAL
dHash
|
810c0e0c00151415 |
|
VISUAL
wHash
|
788381e7ff838383 |
|
VISUAL
colorHash
|
07000002080 |
|
VISUAL
cropResistant
|
810c0e0c00151415,0080401616690000,37d6d6d9984d4954,0082619696618200,0000611696410000,0080211212610000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 14 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 1 other scan for this domain