Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FAF2A4309044B67AC2279DC6F231BB2A32D3E24DDE578601E7F883E057E7DE1D819649 |
|
CONTENT
ssdeep
|
768:EvWeddZFGzXAX5lIB6RAbxZQZgRgJ7KfuQj0nR1rKWQF6ckb9xbZGX2bavobUdjA:EvWQ/0oulI0vnby3VCOvY2 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b83847434747473f |
|
VISUAL
aHash
|
009f8fdfdfffffff |
|
VISUAL
dHash
|
cb363a3a3a485654 |
|
VISUAL
wHash
|
00838f8b8be7e1e7 |
|
VISUAL
colorHash
|
07001000e00 |
|
VISUAL
cropResistant
|
1b343a3a3a4c5654,00200e6969690200,078c8c3068c45922 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 228 techniques to evade detection by security scanners and make reverse engineering more difficult.