Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17CA2627861C157BB41C7CAF1F6696B6AB1D9C70EC623AD86F7F8829727C3D918D10220 |
|
CONTENT
ssdeep
|
384:tx9s+kJE/zY0KNzejNtQ53TB8+/lYBHXYolroUa87x:txWDszY0KNziNu5D+FXYoaUf7x |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c973b602f1cc32e5 |
|
VISUAL
aHash
|
ff0000000000ffff |
|
VISUAL
dHash
|
490e1232d0e16306 |
|
VISUAL
wHash
|
ff80c0104811ffff |
|
VISUAL
colorHash
|
06600018000 |
|
VISUAL
cropResistant
|
000091696999008d,696916766817080c,0040899494948400,4a1c1232f2d8c6e9 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 27 techniques to evade detection by security scanners and make reverse engineering more difficult.