Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18C522E325194227B021B0ACBBE629B5B36F7A27DC9771D02F7F88BE4DBE5E54D801442 |
|
CONTENT
ssdeep
|
384:94u2iY2s6aA5sbKxU/F+eymgQyW/FGnczj4PE5vUKA4oYTq5P1w84I39LQBkeI3V:726/5sbKxU/F+eyny/FGnc34P4vUKA4Y |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
96b425adbc4569d2 |
|
VISUAL
aHash
|
06062e0eff4c0000 |
|
VISUAL
dHash
|
8cacccccb899cccc |
|
VISUAL
wHash
|
06066e6effef2600 |
|
VISUAL
colorHash
|
381c0000000 |
|
VISUAL
cropResistant
|
7e6ee0ccccd490c1,8cacccccb899cccc |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 15 techniques to evade detection by security scanners and make reverse engineering more difficult.