Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T188C2577021116EBF54CBD7B1A3E09B6AD2E4C798C627C69CB2E8C2566FC6C55CFC6240 |
|
CONTENT
ssdeep
|
768:R9vRKpBvqRWXbIsvA9AOYA6UAfamdBosi:g59vo3YG3 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec3c92936d6d921a |
|
VISUAL
aHash
|
fd9f83b191ffffe7 |
|
VISUAL
dHash
|
693a372733000e0e |
|
VISUAL
wHash
|
a580818191ffffc3 |
|
VISUAL
colorHash
|
07000000e00 |
|
VISUAL
cropResistant
|
693a372733000e0e,37b7b73777373747 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.