Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19D82B5BC23809BAE70838777E765B73D9278C7CBE8679149E3E9806267C5C05CD66290 |
|
CONTENT
ssdeep
|
192:aU8i7UVxorfzCir9Z4oHWuoWz99409i07G0V+0eY0AHgFbbg:aU/7UVerrC0f4puo894aikGLA3AF4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cd4c8bb3b3ae8c84 |
|
VISUAL
aHash
|
00000000ffffffff |
|
VISUAL
dHash
|
41303004085aca5a |
|
VISUAL
wHash
|
00000000ffffffff |
|
VISUAL
colorHash
|
060000001c0 |
|
VISUAL
cropResistant
|
0140514951400000,1a1ae7adacebcdd1,80a298baa2ba80a0,4c4cd25a4b94d25a,0030323030303008 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 14 techniques to evade detection by security scanners and make reverse engineering more difficult.