Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F733A76051325AAB029383C1F6B69F9DD0C08341D7378A79B3FC866FAECEC44DD99261 |
|
CONTENT
ssdeep
|
768:K4giEWFrQ0J662WgP04L3MC0hEC63qwg5:NdEWFrQ0J662WgP466wg5 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fbd54dba111584c5 |
|
VISUAL
aHash
|
02a1f04dcd8d8100 |
|
VISUAL
dHash
|
96414099192d2b12 |
|
VISUAL
wHash
|
02f1f4cfcfdf8100 |
|
VISUAL
colorHash
|
30000008580 |
|
VISUAL
cropResistant
|
96414099192d2b12 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 112 techniques to evade detection by security scanners and make reverse engineering more difficult.