Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19D827322B144753B06D381D23AE6638AD3AAC0D4CA66061663BCC6CC17F1D6DC57FF5A |
|
CONTENT
ssdeep
|
384:n8+7+G+kgIIKbjHVgS0IanLh1T1M3fMuh88ZpmnEV/c8GUkOF:n8+7+G+kgIIKbjHVgSCF1O3kuhXOMF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c9cde3832d636929 |
|
VISUAL
aHash
|
607c1818183c3c00 |
|
VISUAL
dHash
|
ccf0323032d4d422 |
|
VISUAL
wHash
|
e0fef8d8187c7e00 |
|
VISUAL
colorHash
|
380000001c0 |
|
VISUAL
cropResistant
|
ccf0323032d4d422 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.