Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14123A8F208A8A6365376C3CD8629FB5EE3C7509ACF624942E3F8879DCF86D50D80111E |
|
CONTENT
ssdeep
|
768:pElh1/4xxn9N97xx9NwZxR9NVBx09NqyTWLUr+oTuR2SZ:pElh1/4xxn9X7xx9aZxR9DBx09IyTWLD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc434b416e3cc1de |
|
VISUAL
aHash
|
00ffdf879fff8f81 |
|
VISUAL
dHash
|
23cc3a3f2b1b3b2f |
|
VISUAL
wHash
|
00ff8f8393fb8381 |
|
VISUAL
colorHash
|
06200038000 |
|
VISUAL
cropResistant
|
03232323232323c3,0b1b3b2f233b3b2b,08006869696826b4,a9acb27274b496dc,a9b4bcf0727ab636 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1217 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 1 other scan for this domain