Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T137B1203822C29AFF51C383F2E751B73D52ECC6A6D6539698A6F0D36D8FC6C158980250 |
|
CONTENT
ssdeep
|
96:tQF4wN0aBu9F7PfXt9biWO76A/FQFGd+JFUcD1FTOVH9r:o4UBgF7H3Y76A/FQFW+JF1D1F6Vdr |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dddd232723962136 |
|
VISUAL
aHash
|
d0ffffff00000000 |
|
VISUAL
dHash
|
9630301032d4d48a |
|
VISUAL
wHash
|
faffffff00240000 |
|
VISUAL
colorHash
|
18001000180 |
|
VISUAL
cropResistant
|
abaaaaa4ab2baba7,828096a6a6c08080,9630301032d4d48a |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.