Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11FC2B97262456A3712A743C6BB567BB573ED80C6C153131089FC4368CEEAD86EC3B792 |
|
CONTENT
ssdeep
|
768:Z4rbT7PAkAsbRkqXbmfj9SEEcYylrT0fNJ:ZoT7xiqXbmfjdvYylrT01J |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c743383bc3c0c737 |
|
VISUAL
aHash
|
200070746420007e |
|
VISUAL
dHash
|
d410c0cd4d4ab044 |
|
VISUAL
wHash
|
6e007e7e7c6000ff |
|
VISUAL
colorHash
|
380000006c0 |
|
VISUAL
cropResistant
|
d410c0cd4d4ab044 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 6300 techniques to evade detection by security scanners and make reverse engineering more difficult.