Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19C3233305251E53B009792D1F6F62BAF36FAC2D6EA43029653F8436E4BCFC94CD16492 |
|
CONTENT
ssdeep
|
192:nHm1II/m/b/mPIdISZlV7v2auxxViJNZx9Ru5QKH2EuXQVMEMPPxeDgNyIp:Hm1II/mzOPIdVuxX2xRekAdMHxeUNyIp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ce9b3466666419ce |
|
VISUAL
aHash
|
003c3c3c3c081000 |
|
VISUAL
dHash
|
067171f06170b430 |
|
VISUAL
wHash
|
803c7e7e7e38183c |
|
VISUAL
colorHash
|
30240030000 |
|
VISUAL
cropResistant
|
674b6ce4dcd8f8b9,b59716363617b1a9,5e57d4b6b6a4b7b4,9585369696363531,067171f06170b430 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 24 techniques to evade detection by security scanners and make reverse engineering more difficult.