Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11E63746012335AA701A3C2C0B6F69F8D91C4C354D2638E79A3ECC75EDECDD84ED89666 |
|
CONTENT
ssdeep
|
768:w4egV3T1qw+LVB8Wn1gnuNKRmmB4zxRtO74l+:LvV3T1qw+LVB8Wn1ShOxzfl+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b2d56d2814b749f2 |
|
VISUAL
aHash
|
0280ee2e4f818180 |
|
VISUAL
dHash
|
b64d4c4c8c03251b |
|
VISUAL
wHash
|
0281feeecf81d781 |
|
VISUAL
colorHash
|
300000104c0 |
|
VISUAL
cropResistant
|
e8c4e262e2f294c0,b64d4c4c8c03251b |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 112 techniques to evade detection by security scanners and make reverse engineering more difficult.