Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13B33967072115A7F90E38BE8F328B37A91EAC38DC60B828592ED83755BC7C46AD71354 |
|
CONTENT
ssdeep
|
768:gRQKgstsIX1Zth7vRcnNAzBQV+jyoEAQiVqV3OVTV0uoBgV1r5/tkYa327d:NClZt5RcNO06Hqj327d |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c3b43cbc94c3b43c |
|
VISUAL
aHash
|
4600607674606000 |
|
VISUAL
dHash
|
9423ccccc4ccc420 |
|
VISUAL
wHash
|
5e60767e7e7e6000 |
|
VISUAL
colorHash
|
38000038000 |
|
VISUAL
cropResistant
|
9423ccccc4ccc420 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.