Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D742B5B29211623B19175EC5BA7B63EE72E6C14CDD53089466FD4BDC0BE2C80F84A8D6 |
|
CONTENT
ssdeep
|
192:U5BVBb/wFjwjwtPyNFkV7P5PyG9acNleufG9acNltkS3Ca9KbtKpCBpXx/FBKiy:tF8yPi6PZJuZ6SSa9AAW97y |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
936d926c93926cc7 |
|
VISUAL
aHash
|
0420340c20002e2e |
|
VISUAL
dHash
|
94cbe9c9c838d8d8 |
|
VISUAL
wHash
|
077b7d2c64007e3e |
|
VISUAL
colorHash
|
30180002000 |
|
VISUAL
cropResistant
|
a2a4908ccc90a4a2,f0e01833b33b3b33,94cbe9c9c838d8d8 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 284 techniques to evade detection by security scanners and make reverse engineering more difficult.