Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11CC242F4A3C13BBA05838AF7625A9B0F9DE5CA5AC527D5CD63F1C267778AC1D8980340 |
|
CONTENT
ssdeep
|
192:rvdLMx59ujQHp1S8b91jZv+az6FcwHjnEiCQQp6pIpbW28MFMS4FFXFfFncLtsNr:rvdLMx5wjQJcfiU42rFZ5FC+yKPCO |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b838c9c7c6c61b99 |
|
VISUAL
aHash
|
ff838387ffffffff |
|
VISUAL
dHash
|
631e1b34c20c4e32 |
|
VISUAL
wHash
|
91010103ffe7ff83 |
|
VISUAL
colorHash
|
07009000180 |
|
VISUAL
cropResistant
|
631e1b34c20c4e32,54dde9e9f1d3c103 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.