Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1864294B16090AA331293D4D6D6386B5FB1C3479AED135F06A3F943DD9BCECA2DD01066 |
|
CONTENT
ssdeep
|
192:p3Kont+KGRAomHRZtBYAYreOzxED8VchoNdSVpHbd+EpEaU3aONKU75gGAOx9:FKCGRaV5YaSxEDuIiSVtbd+Ey3t9 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
936c9d6c923e91f0 |
|
VISUAL
aHash
|
02606c0c64000c6e |
|
VISUAL
dHash
|
a6c7c9cdccc338d8 |
|
VISUAL
wHash
|
03636f6f6e200e6e |
|
VISUAL
colorHash
|
38600000080 |
|
VISUAL
cropResistant
|
cc322bcc9c79cc69,b0a0c8b2b28e8e96,a6c7c9cdccc338d8 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 28 techniques to evade detection by security scanners and make reverse engineering more difficult.