Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16733A6326180BD3B418783C1B2F2936632E9C149D69312A5A7FD879D4EF3CD4ED4E266 |
|
CONTENT
ssdeep
|
1536:em3IIronXtge9COsRvZ71QtEUeReM0Q9nSLsel5n:H5AXtgTOsz71QtXeReM0Q9nSLsel5n |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc3cc336663133ce |
|
VISUAL
aHash
|
003c1c1810007c7c |
|
VISUAL
dHash
|
947171322078d0d0 |
|
VISUAL
wHash
|
5a3c3c18183c7e7e |
|
VISUAL
colorHash
|
30002200010 |
|
VISUAL
cropResistant
|
947171322078d0d0 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 3382 techniques to evade detection by security scanners and make reverse engineering more difficult.