Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AAC28472D481BA3702ABC3D29675A36772D8C19ADA07130852FDC3EC4BCAD55FC2B642 |
|
CONTENT
ssdeep
|
384:v5NTuII1c9CbkRSiy7gqTPc0byCM5ZMxe/ceUsv9uObshKSO0Uleef2u9gM7TU0N:vCIIKCbkRSiyECk0GCMl0y9gQJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c3e538313c6cd2e5 |
|
VISUAL
aHash
|
006870306c6e002c |
|
VISUAL
dHash
|
95c9c4e4d8d868c8 |
|
VISUAL
wHash
|
416d7c7c7e6e003c |
|
VISUAL
colorHash
|
38000e00008 |
|
VISUAL
cropResistant
|
95c9c4e4d8d868c8 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 9 techniques to evade detection by security scanners and make reverse engineering more difficult.