Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F3A284712110AD7F108786F4F7A4AB25969E8395C5539B2E63EC83F15FA6CE1CE4A340 |
|
CONTENT
ssdeep
|
384:tiwwgjgDHbgUfipHwhKaap0iBxfaAaIkBm:A9gjgPgUKpHwuRDxkBm |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed12924d6f933992 |
|
VISUAL
aHash
|
fd9f8b91f1f1ffff |
|
VISUAL
dHash
|
eb30363323339318 |
|
VISUAL
wHash
|
380c8280f0b1ffff |
|
VISUAL
colorHash
|
07006000040 |
|
VISUAL
cropResistant
|
eb30363323339318,9a76edab43e5b135,138a9a8292cd8211 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.