Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AF326431361436BF46C382F8762167FEF3858549DA2B8BC662F0824D27C6DD1CE607A9 |
|
CONTENT
ssdeep
|
192:6kQcvZtP8WqSnNSvB3F363q3H3+fiRHPJgAa+BU3dPLfx06UpSzPZ6C:rQitRqW4vB3F363q3H3+anTG3hfC5bC |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
96b469696a6a496d |
|
VISUAL
aHash
|
060e660e06300000 |
|
VISUAL
dHash
|
2ceccc8c6c616869 |
|
VISUAL
wHash
|
cf0e6e6e0e3c283c |
|
VISUAL
colorHash
|
30000200030 |
|
VISUAL
cropResistant
|
f29e76725159636c,2ceccc8c6c616869 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.