Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B8050FF12252593B467BC1D1A2B587AEB0E1F20CC593820E41FE52E9D7CBC76BC61E64 |
|
CONTENT
ssdeep
|
3072:4rDHuw3DFa6b3NMCXVlR/f3Pv/UVew9WJB4CAy8YrvA2JExAoSLWEWr9TmBc3EiQ:eP3uAogpJ5 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ccccf43371307476 |
|
VISUAL
aHash
|
463c1818383c1c18 |
|
VISUAL
dHash
|
ac61a032515555b2 |
|
VISUAL
wHash
|
cf3c183c3c3c3d19 |
|
VISUAL
colorHash
|
38007000040 |
|
VISUAL
cropResistant
|
ac61a032515555b2 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 32 techniques to evade detection by security scanners and make reverse engineering more difficult.