Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B0217B3024929D3312E293D876E35A0A72C1F745CFDB670647E883D90EE7CA5DC1A045 |
|
CONTENT
ssdeep
|
24:hR/CIxA02OM3MNrsKVWUNGFnHD52RM32v7PgyCjm2r8g:TaOM3M1sAXNij52Rbv7PgyCj3b |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
99992c6c96b331cd |
|
VISUAL
aHash
|
1818183c3c000000 |
|
VISUAL
dHash
|
3232706970700400 |
|
VISUAL
wHash
|
183c7e7e7e7e0000 |
|
VISUAL
colorHash
|
38007000000 |
|
VISUAL
cropResistant
|
3232706970700400 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 24 techniques to evade detection by security scanners and make reverse engineering more difficult.