Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18CB27470931120311663C7C5BAE5BBACC39AC38EC6294C79F36C8256178EDD8EF22E54 |
|
CONTENT
ssdeep
|
768:NturKhKMGMOM9N6cqhEI1Fp/ykSOhkifEi1Fp/qEWe1Fp/lEee1Fp/BXEu1Fp/RG:NturJfZYYXv1bSOKiN1+e13e1r1re12+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c01f39c6e6399b64 |
|
VISUAL
aHash
|
000008f0f2ff40c0 |
|
VISUAL
dHash
|
6ccc5ae4e4e1939c |
|
VISUAL
wHash
|
00263efef3ff40c0 |
|
VISUAL
colorHash
|
18038000000 |
|
VISUAL
cropResistant
|
14944b5bb7b6546b,9a1275336c5a4664,2474c5e7b4dc5256,524a3d424ab23636,960e6b5c5830ad49,6ccc5ae4e4e1939c |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.