Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A5D28371A085BE3B02A782D26B76636B32DDC28AD557031457FCC3EC4BC6DA1ED1B606 |
|
CONTENT
ssdeep
|
384:B+ZrK3ZIIQYSkXk8GF9XYBm2Is0MwUMxBJAFPEOWxDXSjrnX7OOi44h2oSiH7d+q:srCZIIKkXk8GF9X2m2j0VYta+Uh+q |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e363c8cbcc495b4c |
|
VISUAL
aHash
|
f9c3c3c3e7e7ffff |
|
VISUAL
dHash
|
2b0c8e0e0c0a1600 |
|
VISUAL
wHash
|
00c3c3c30327033f |
|
VISUAL
colorHash
|
07000600030 |
|
VISUAL
cropResistant
|
2b0c8e0e0c0a1600 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 130 techniques to evade detection by security scanners and make reverse engineering more difficult.