Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17C13D87812A0643FE5138AF9F6A17774519DC2AED753C710F2ED023A4FCACD29A32644 |
|
CONTENT
ssdeep
|
768:DFbd5w/ePNcio8NhOz8Z9JE9oHzYBaLG6JqvWzBzLpkaNcFe:2/ePNcd8NhOz8Z9VHzYB+PkgcI |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8d98c773a6334738 |
|
VISUAL
aHash
|
3c18181f03203c3c |
|
VISUAL
dHash
|
d0f0f03337c8c868 |
|
VISUAL
wHash
|
3c1c3c1f1f383c3c |
|
VISUAL
colorHash
|
380000001c0 |
|
VISUAL
cropResistant
|
d0f0f03337c8c868 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 16 techniques to evade detection by security scanners and make reverse engineering more difficult.