Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C9F186705161663704BB85D1B6E2276F76E6C1CAF9830296D2FC83AD0BDFC95EC0B942 |
|
CONTENT
ssdeep
|
192:BgCzsIIhAHqsWscIRPpJmt93f0PoTU9uwX0u:BgIsIIhAHqvwMcQTkuwX0u |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9b9b24642c8b9b9b |
|
VISUAL
aHash
|
00003c3c18001000 |
|
VISUAL
dHash
|
4886797932303008 |
|
VISUAL
wHash
|
81347e7e7e3e9900 |
|
VISUAL
colorHash
|
38000038000 |
|
VISUAL
cropResistant
|
ccaca9a9ac8cce8b,5555151757555747,4886797932303008 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 28 techniques to evade detection by security scanners and make reverse engineering more difficult.