Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T117A1F0B4A361592706B7C3C2AF514B3B31D8E349DEC6098002FDC39D9F96C85ED8749A |
|
CONTENT
ssdeep
|
96:nxoPB2Vgk6N6+hm23WW2Sd5Lu9qerjPK8EKfmioOi:xoPegk6N6Om23WlOC9qerb5EKfmzD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cfc932b289cde630 |
|
VISUAL
aHash
|
ff00383818300000 |
|
VISUAL
dHash
|
2340606270606070 |
|
VISUAL
wHash
|
ff2038bc3c383c3c |
|
VISUAL
colorHash
|
38000000038 |
|
VISUAL
cropResistant
|
ab2b1ada9a8d4dcd,2340606270606070 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 85 techniques to evade detection by security scanners and make reverse engineering more difficult.