Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BA2393605232196B01A382C0E7F7DB58A1C48381D7634A79E3FC876FAECDC54FC5A6A5 |
|
CONTENT
ssdeep
|
384:KITgWERclndvcxNaLP3m/UZO48WhoeVHG86/jRVXQ12v6G/9PqaTV1giUSqZZRPV:Krm+NK3m/UZO48Whoeg/Vwq64jIVVn |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b2d56d28909645f7 |
|
VISUAL
aHash
|
0280ee6e4e818181 |
|
VISUAL
dHash
|
a61d4ccc8d03250b |
|
VISUAL
wHash
|
0285eefe6f81d381 |
|
VISUAL
colorHash
|
30000010480 |
|
VISUAL
cropResistant
|
e894b2637362acf0,a61d4ccc8d03250b |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 112 techniques to evade detection by security scanners and make reverse engineering more difficult.