Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19AF2F831A2DC1A3F45A307C8F652E767B2899548F1D0439A6AFDD3BC1BD5EC6EC01846 |
|
CONTENT
ssdeep
|
768:/PZKbqemlUcuXwktCPw+XnOoAjdTcPWI9Z0B7c/:nZKbqemlUcuXwktkOfB2F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a6d9996699996698 |
|
VISUAL
aHash
|
9ff7cfcfe7e3273f |
|
VISUAL
dHash
|
2016169a0d86c65a |
|
VISUAL
wHash
|
9fc3c3c7c3430707 |
|
VISUAL
colorHash
|
07400000002 |
|
VISUAL
cropResistant
|
2016169a0d86c65a,0f5415971470359d |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 930 techniques to evade detection by security scanners and make reverse engineering more difficult.