Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AB6214B22040A63B43A7C2D57A36133FE2A286C4D9E71F0623FD4B4E5AC6EC5ED1155B |
|
CONTENT
ssdeep
|
384:djw1knisutAvRMbEonOySkfRX44odQ1k04n8emqJFB:GH44mIC8ad |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cfc1323ab8c9c1ce |
|
VISUAL
aHash
|
0030787838383010 |
|
VISUAL
dHash
|
90e2e2e2647266e6 |
|
VISUAL
wHash
|
40f0f8f8f83e3632 |
|
VISUAL
colorHash
|
38018000c00 |
|
VISUAL
cropResistant
|
5071d3242c4dc519,6555d522332626d4,3b37e7d9585a5226,90e2e2e2647266e6 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.