Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1ED24CB70435A8D7695150187B634F3761AF2B300F7E023014AFB66E6A6C98F8DA5F3AD |
|
CONTENT
ssdeep
|
384:YTrbasG5J0JsR3OC1c3uH2Rv8zBrydHjDcNcIK/6Su+M8eYqBtFJrc/0OAB07cax:QxGxH2RpZIcIK/6SoFtYkB0waT0JpX27 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92936d6c34cd65c3 |
|
VISUAL
aHash
|
006c6e2e2c001800 |
|
VISUAL
dHash
|
80c8c8dc4c303014 |
|
VISUAL
wHash
|
406e7e7e7e18183c |
|
VISUAL
colorHash
|
38001008400 |
|
VISUAL
cropResistant
|
80c8c8dc4c303014 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.