Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E45124700DC5793752AB82D85E23DB9962D6A71DDE47081165F8A7C807C6EDABE03034 |
|
CONTENT
ssdeep
|
48:ESQ1fvGyq8vaSMnAE11um/+wOGXHGfxf3HGOcI8HGlcI8YQCoaM7lNvAui:iJGyq8yAE10lD8HCHb8HE8YYaM7lNvAJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e66699999926cccc |
|
VISUAL
aHash
|
ffe7e7e7e7e7e7ff |
|
VISUAL
dHash
|
084d4d4d4c4c4c44 |
|
VISUAL
wHash
|
2723272707072727 |
|
VISUAL
colorHash
|
07200018200 |
|
VISUAL
cropResistant
|
084d4d4d4c4c4c44,735119092b0b0727 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 94 techniques to evade detection by security scanners and make reverse engineering more difficult.