Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1150333605233166B02B382C1E6F79B8D91D48294E7634B79F3ECCB5E9ECDC48BD59122 |
|
CONTENT
ssdeep
|
768:hqBA/VjJpZrz8WHHbHDhyj/Vu70zInev6Yr6:hf/VjJpZrz8WHHR2anw6Yr6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bad56d2915b451c6 |
|
VISUAL
aHash
|
0280fe6e64c18181 |
|
VISUAL
dHash
|
96494cdccc9b2525 |
|
VISUAL
wHash
|
4285feee6fc18381 |
|
VISUAL
colorHash
|
300000084c0 |
|
VISUAL
cropResistant
|
96494cdccc9b2525 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 112 techniques to evade detection by security scanners and make reverse engineering more difficult.