Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T170A254346154973B268783D8B3227A7AA291F205CB724291A6FCD314CBCAFB5DC73785 |
|
CONTENT
ssdeep
|
192:EL+Qz1C1WNO5ibBrrXTKd9OuSnuJqd1WFY3TV+4KNAVtWKk:ELRyB5ilrrXOdHSnuJql3ZhKS8p |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9c9d9d62616565c6 |
|
VISUAL
aHash
|
1e3c3c0004000000 |
|
VISUAL
dHash
|
f070f012d4d4a200 |
|
VISUAL
wHash
|
7e7e3e04747e5a00 |
|
VISUAL
colorHash
|
380000001c8 |
|
VISUAL
cropResistant
|
5292ca4a4be8ce4f,f070f012d4d4a200 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 212 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)
Found 4 other scans for this domain