Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10EA2E762505AAC2E4B7293CBF6E11B7BD3E7A216E8327847C6DCCB591BD8D11D4A310C |
|
CONTENT
ssdeep
|
384:Xm05kGkD6VwZb0uBkLkbOYIGl1ysPm71SQcgSOkuY:SYuCL+6qAnUQbA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cf8387c7c7236322 |
|
VISUAL
aHash
|
3d3c003c38303c3c |
|
VISUAL
dHash
|
4961686961616969 |
|
VISUAL
wHash
|
3d3c3c3c3c383c3c |
|
VISUAL
colorHash
|
38000e00000 |
|
VISUAL
cropResistant
|
4961686961616969 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.