Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C9D23170134827BF528B89F6F2367B3A31EAC349D96BC465A2FC83561FC2D44DC62690 |
|
CONTENT
ssdeep
|
384:+dhOYg1LJRPtzFSoT7oGeXPuofHHA6vcSonfJ:0k11VFSqoGKPuo/gBR |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9e9c61619e9e6465 |
|
VISUAL
aHash
|
9818003c3c002020 |
|
VISUAL
dHash
|
7430647968465454 |
|
VISUAL
wHash
|
9e183c3c303e3e3e |
|
VISUAL
colorHash
|
38000000007 |
|
VISUAL
cropResistant
|
26806d05307500a0,7430647968465454 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.