Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T192F165B18145AD39B677C584E770A6AB7144C285C35B1B044BB1133EE8C7AA6AE722EC |
|
CONTENT
ssdeep
|
96:hZu9dHe1YXPKJK0bJKfDJI1Ku88EZOdkNw9aoKwRCdyp4R3/Ska5akr:Tu9wm/0dsw9zKw4dLRPSpaA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b3268c996667cc99 |
|
VISUAL
aHash
|
3fa7a5a58defefe7 |
|
VISUAL
dHash
|
694d4d4d190b1b0d |
|
VISUAL
wHash
|
3f270101898defe7 |
|
VISUAL
colorHash
|
07001000680 |
|
VISUAL
cropResistant
|
694d4d4d190b1b0d |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 1288 techniques to evade detection by security scanners and make reverse engineering more difficult.