Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17DB285B3A0C27D3702B7E1D296B6937B71D6814DC9774960A3FC83AD67C0D90A96A343 |
|
CONTENT
ssdeep
|
384:KhNw0503svrUUHTeAn/g8SD/6YmlNWJkz/Dwg8W3oFhrKNH3lJs54i:GSsQUHTXn/g8Y6YmHWmzbwghoFhrKNH4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8cab23ac8b8eae33 |
|
VISUAL
aHash
|
8100183c18181000 |
|
VISUAL
dHash
|
6310617032b03000 |
|
VISUAL
wHash
|
ff3c3c3c3c3c0000 |
|
VISUAL
colorHash
|
38000000e00 |
|
VISUAL
cropResistant
|
6310617032b03000 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 138 techniques to evade detection by security scanners and make reverse engineering more difficult.