Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BA5265BB40006A3B42D383D9A235737F939796C5EA831B1A43FA4B5F4AC6F50EC16467 |
|
CONTENT
ssdeep
|
192:ZeTilIIoUMTQy55CGeRLb9MqrH/N2H/h/r6E/ka/+cz/rm9HzY:ZeCIIrMk8CGuJHI1rPF+cjrm9k |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc18e7c6c6e51c38 |
|
VISUAL
aHash
|
ff8f89db8edfe3ff |
|
VISUAL
dHash
|
263c333238300e06 |
|
VISUAL
wHash
|
df0f000088ffc3ef |
|
VISUAL
colorHash
|
070060000c0 |
|
VISUAL
cropResistant
|
263c333238300e06 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.