Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15EF1ABB1A286D93B07F392D0E662A72FB2D1814CEE970B5103F983DD4BEAD41FC22455 |
|
CONTENT
ssdeep
|
96:n0l841YSYhqKsjhwiSxibq8mulRSlUnY4v19ZujyxBeeQrQAm:0l8EROqKslwihbq8qlkZujyxBFH3 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9a6c182cecbb6d92 |
|
VISUAL
aHash
|
813ca4a4b4000c0c |
|
VISUAL
dHash
|
33296969696379f9 |
|
VISUAL
wHash
|
899fadbcbca03c0c |
|
VISUAL
colorHash
|
38600018000 |
|
VISUAL
cropResistant
|
ffce4b6bdfdf3fff,33296969696379f9 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2311 techniques to evade detection by security scanners and make reverse engineering more difficult.