Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T137F214F18395853F9AFA43F0E952A23B63CF6648DB85C39401B43B68C5BCDD95E05CA8 |
|
CONTENT
ssdeep
|
768:87Pfgggnr1BOMXBVN6WOMXBVN6myH0gDX:88ggnrzOMXBVN6WOMXBVN6NtX |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e00f1fe6e3390ee0 |
|
VISUAL
aHash
|
010001e0f0f0e040 |
|
VISUAL
dHash
|
3386279b81a49880 |
|
VISUAL
wHash
|
ff0383e3f1f0e060 |
|
VISUAL
colorHash
|
380010081c0 |
|
VISUAL
cropResistant
|
95d5ddf9a4273a5b,b4b465a593224a6b,3386279b81a49880 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 4134 techniques to evade detection by security scanners and make reverse engineering more difficult.