Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12332DA333441FE2B139792E67675672ED3828A16C2962B05B3ECC62B6BC7E52C85C056 |
|
CONTENT
ssdeep
|
192:auyEIIx7y3LPtopz6mCT3yrBGnj3ivrFYyya5D:aXEIIs3L13TyYnjyTFaGD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c2299d7aab4dc38a |
|
VISUAL
aHash
|
ff006040000000ff |
|
VISUAL
dHash
|
1b9cc4c48d85a061 |
|
VISUAL
wHash
|
ff4c70e0c06070ff |
|
VISUAL
colorHash
|
06e00000000 |
|
VISUAL
cropResistant
|
042bcb2323cb2304,6000000000600020,99d0c4c6858d8521 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.