Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11DF230716059FE3761D382E1A271976F32D2E386DE4B136517F883AC4BC6CC8DC2A54A |
|
CONTENT
ssdeep
|
768:QJ5ik3udoifFjV0g/T0SDMbKaf0eHrsuBER2B9sZzqJEOv9stnBxMd0Gh6pTIL:QBSDMbKaf0eHrsuBER2B9sZzqJEOv9s+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c365393c3c3cc6c3 |
|
VISUAL
aHash
|
8066760670705c7e |
|
VISUAL
dHash
|
32c4c4c4c8c090c8 |
|
VISUAL
wHash
|
8066700670ff7c7e |
|
VISUAL
colorHash
|
380010001c0 |
|
VISUAL
cropResistant
|
32c4c4c4c8c090c8 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 23 techniques to evade detection by security scanners and make reverse engineering more difficult.