Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1ED922EB1A540AA3B91C382D4EB3557BB73E0C28AEE43065663F8C36D4FD2D85DD23564 |
|
CONTENT
ssdeep
|
192:Kb9KAzijoqluKhi4gWAS4ZQ4vdeSZTAPG065R9VP5yg3bp/blz:i9KTSFJhlAu0ITegrpV |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9aec13ed9343e918 |
|
VISUAL
aHash
|
ffffdffffbfb000c |
|
VISUAL
dHash
|
6b3237372623d8d8 |
|
VISUAL
wHash
|
f9df8f9f93130004 |
|
VISUAL
colorHash
|
0e000008408 |
|
VISUAL
cropResistant
|
2be2333737372689,a2c0c2b0b0e0e0b0,0551a7d4d4239545,60542832324c6041,024818d8d85cd8dc |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.