Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T120036431545A243B027B2ADA77657B1EB0E7D39ECA034A0437FC93EA4FC6E60F924156 |
|
CONTENT
ssdeep
|
768:MtyS6ZL+uOKoRNnvJJyRvqB6sCW4fIdZQcKywgk:IyS6Z0K8jOIdOcKya |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ab9692f3276cc12c |
|
VISUAL
aHash
|
ffff7b00c1ef010c |
|
VISUAL
dHash
|
4c29f2330bcb23d8 |
|
VISUAL
wHash
|
2cff7a00c1ef013e |
|
VISUAL
colorHash
|
08001000380 |
|
VISUAL
cropResistant
|
0c000808c0e2f8fc,24e0c0b2b280c221,e4a7c30a23d376b4,2e9ed697cd6d9f13,6d296364f132a88d,1a8ae8ccb231ccce,4c29f2330bcb23d8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 37 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 3 other scans for this domain