Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1607231B0A268AA3741E387D66362537772E7418DCA562300A3FCC3EC5BD5EC6ED23549 |
|
CONTENT
ssdeep
|
192:41tIqPC8b6bydfspY7s1ZhYSz6G/Keu5lwxwsz/JDdNJo4NgBpcj64pdu6H:AtIqPCQV37ojNmG//+uwsz8yj6YduS |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
91916e6e91916e6e |
|
VISUAL
aHash
|
000000ff18000000 |
|
VISUAL
dHash
|
118032d8f0330000 |
|
VISUAL
wHash
|
99183cffbc3c1819 |
|
VISUAL
colorHash
|
38000c00010 |
|
VISUAL
cropResistant
|
49482a1a9bb94945,cbcb631bdb5b24a4,118032d8f0330000 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 288 techniques to evade detection by security scanners and make reverse engineering more difficult.