Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13B5283B110165E7F25C382B5F331FF4AE189DB42CA5BCA4863E5C2576FEAC90CC80226 |
|
CONTENT
ssdeep
|
192:k/IAMZbmw9VCVM306yTU+N7eT5jFeTM40yu/mtb5z1WzzQ/Cy9amW:k/Ez9Vd0hTUWC5j8Mvyu/mttZWY/CUS |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92936d6d963c9692 |
|
VISUAL
aHash
|
020c2e6e6e040000 |
|
VISUAL
dHash
|
e4c8c8c8c8cc10f0 |
|
VISUAL
wHash
|
7e6c6e6e7e2e0018 |
|
VISUAL
colorHash
|
31000007000 |
|
VISUAL
cropResistant
|
f8d8d0d8d8f8f49e,a2801b2b231380a2,a2c827272717a8a2,e4c8c8c8c8cc10f0 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.