Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CB02A6B34704326A8B9250D476293BEFC26B164DF3014DFC72EC841A67E5E94C2B78E9 |
|
CONTENT
ssdeep
|
96:Hx65J/PT85csyRn2GMu2m0X04rBNFO9w5cefMqEmbMkxeHR2/uKLSv0x:Ho3PTfsYnl25NrDFO9cE1mQSyW5LSvG |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a5351fb4a58d3487 |
|
VISUAL
aHash
|
c280025b67467923 |
|
VISUAL
dHash
|
062246b28e8ceb62 |
|
VISUAL
wHash
|
f3e0035b6346fd03 |
|
VISUAL
colorHash
|
30008080201 |
|
VISUAL
cropResistant
|
062246b28e8ceb62 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 615 techniques to evade detection by security scanners and make reverse engineering more difficult.