Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DC83433773040A69AB139FE4F4439B9041BEE325E513E02CC2BDA6364DE6CE3957DA46 |
|
CONTENT
ssdeep
|
1536:10kgc1PjogzB2nxOC1y2Svx7BSvEtNJDrrVEIw:19xDrrC |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92926d6d3992d2c7 |
|
VISUAL
aHash
|
087c7e2c04203018 |
|
VISUAL
dHash
|
d0cccdede8c0c0f0 |
|
VISUAL
wHash
|
7c7c7e3c3c20307c |
|
VISUAL
colorHash
|
38002000180 |
|
VISUAL
cropResistant
|
e0bc6549ecd0b0e0,d0cccdede8c0c0f0 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 28 techniques to evade detection by security scanners and make reverse engineering more difficult.