Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T180419871858ADC77D09F50E5D9B2AF2A32C1C946CF5F678296F4938E0FC0E95CC264A2 |
|
CONTENT
ssdeep
|
24:hR0sCod4nPzyHXKkPfziCLfQTXk7gX/8gXogXCgX0tgX+D:TB4mHxmC8TXk7gX/8gXogXCgXkgX+D |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c01f3fc1c03f3fc0 |
|
VISUAL
aHash
|
181800787e400000 |
|
VISUAL
dHash
|
32b21dc0c48cb4a4 |
|
VISUAL
wHash
|
9818007e7e767e1e |
|
VISUAL
colorHash
|
38007000000 |
|
VISUAL
cropResistant
|
7262626202720ada,7a22222232f0fcff,32b21dc0c48cb4a4 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 1 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 1 other scan for this domain