Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14873D6B46291036F536345E8B6B39B5A909AE31DC7339988A7AC10F26FD5CC1EC533C9 |
|
CONTENT
ssdeep
|
1536:kOt/tTS5rRz/bhVSPJl1BLIkiqTvlPdRz/bhVSPJl1TpwhKQ61CvZ8rE61CvZ+0T:ht1yn1e61CvZh61CvZoll/Bs1p3tBOuv |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fb77157c121b0691 |
|
VISUAL
aHash
|
0081e381c5f1cb7f |
|
VISUAL
dHash
|
0c22430b0b233b9a |
|
VISUAL
wHash
|
0081e381c7f1cbff |
|
VISUAL
colorHash
|
0b003208000 |
|
VISUAL
cropResistant
|
8ccc9886c0cb48c0,22434b1b0f231bbc,e3c1a8c8e4697918,aaaaa4a6d4aaaaaa,787994ac8ce09c9c,b89ca6aa92aa98d8,2089c7b0a0a0c2a4,0c22430b0b233b9a |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.