Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1186141709D419A3B0A6283D12775A75FABC19A89E9078E455BF9C73C8BCAEC2CD35210 |
|
CONTENT
ssdeep
|
48:OgViQp5zCH0aa6Gaw7TmNjsThQDKZYR/aGH/qxR/quaG2ELEzpxUNmopm:Nj5zEGl7yuhQpIZx8uHrLElCNfc |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b3ce649966466699 |
|
VISUAL
aHash
|
ffffe7e7ffe7ffc3 |
|
VISUAL
dHash
|
08284d4d5a487a4d |
|
VISUAL
wHash
|
00242424efe7efc3 |
|
VISUAL
colorHash
|
07000000007 |
|
VISUAL
cropResistant
|
08284d4d5a487a4d,51ecb2320c30b045 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.