Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BC026339A1C4BE3E00D7D3EDEB31935E22E0DA81D45B47486BF6874C8ACAE59CD0E059 |
|
CONTENT
ssdeep
|
192:/9d8k66/c7KULPDmStAuhchJqDOo7uQHFqjI:/Qk1wK0aWNhchJZCqE |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
880aeee6ac8ce6ce |
|
VISUAL
aHash
|
1f000000ffffffff |
|
VISUAL
dHash
|
7fd9f3f7cf082a2b |
|
VISUAL
wHash
|
030000003fffffff |
|
VISUAL
colorHash
|
060000001c0 |
|
VISUAL
cropResistant
|
00606363636800ff,b2a8a629c236aa47,710c0d00222a2b2b,ffddd1fbfbf7f7ff |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.