Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T139414270C154A92F824383C84258B39F35CD928FEB4B03025AE863789BC6DC7FC2521D |
|
CONTENT
ssdeep
|
48:TiD2U+vsI/iFsmUHv28uC1fyBjF8rV3pG4Dg:TiDcvsgi9U2ChyBjE3pvDg |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b399cc2666cc9933 |
|
VISUAL
aHash
|
ffffffe7e7e7ffff |
|
VISUAL
dHash
|
0418224d4d4c0c10 |
|
VISUAL
wHash
|
c0ecfce424243c0c |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
0418224d4d4c0c10,6169606128b2b24d |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.