Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12BE34623422979264437C6D134AA5B7BD1A6DD9FFAE70A010EDCCBF72AF9C90701A11D |
|
CONTENT
ssdeep
|
1536:DhpR4nXBKpSpFl26v60wOdXEAzXX8FAgs+aFyX:DPUM8/RxYN |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b535ca4aabca25b4 |
|
VISUAL
aHash
|
000203030302ffff |
|
VISUAL
dHash
|
319696969696190c |
|
VISUAL
wHash
|
0003c7070707ffff |
|
VISUAL
colorHash
|
3a003000180 |
|
VISUAL
cropResistant
|
9293c0e4f0312196,129a60000c288e0e,33769696969696f6 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 33 techniques to evade detection by security scanners and make reverse engineering more difficult.