Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13C6274B630447D2B42D3D2C97722673BE1D6414ED5CA0A40A7FE8B1A0DE6E90FE4B54B |
|
CONTENT
ssdeep
|
192:GHX3Yi748aXsIIv1vgL3+Gr1N5hUTyeu6o13oE88B0LLK2Oj+rvZMmFLXcPCkfvw:GHYi79tIIvNgB3aao98X2LFDmnEUUZ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc4cba49b4ba38b6 |
|
VISUAL
aHash
|
9ff0f0f0f2f0f9df |
|
VISUAL
dHash
|
33f23474c6d2633c |
|
VISUAL
wHash
|
1870b0f0f0f0f8df |
|
VISUAL
colorHash
|
06000010180 |
|
VISUAL
cropResistant
|
33f23474c6d2633c,08a4868c94330390,a0a48d8da7a3a780,4a319696172b0b40,a01e0f8cccb2aad0,4105b2b4ae6b0141,1860616969696006 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.