Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T125034F71A451FD3B017FC6D272B9972F72E6C248DA43026053FC83AD5BCAC95ED2A641 |
|
CONTENT
ssdeep
|
384:tVtvdYOrhuGSPfMb9SHJ8wTGE+SZxABDA96EdGudoC6ghzdn/W:hvdLpS3MAlTGE+e/7dGuLzd+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc919345ccd2517d |
|
VISUAL
aHash
|
fe8f8f9f91f0ff9f |
|
VISUAL
dHash
|
c033373733932c30 |
|
VISUAL
wHash
|
7e0f8f839100bc9f |
|
VISUAL
colorHash
|
07000600030 |
|
VISUAL
cropResistant
|
c033373733932c30 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 3527 techniques to evade detection by security scanners and make reverse engineering more difficult.