Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1486250B1B294FA3702D783E2B772476BB2E8C645D917162546F8C36C4FD6C99DE23202 |
|
CONTENT
ssdeep
|
384:EyWzDWbigCU+2N0JY/a2Yb/pjtmPqNgYGm:EZDQmH//p |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cf1b924683df4781 |
|
VISUAL
aHash
|
3c00000030b0ffff |
|
VISUAL
dHash
|
e8717161606060cc |
|
VISUAL
wHash
|
3c000818f8f0ffff |
|
VISUAL
colorHash
|
19000000e00 |
|
VISUAL
cropResistant
|
aa8090c4c4d080aa,60604060f0ccccc4,e069337161606060 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 7 techniques to evade detection by security scanners and make reverse engineering more difficult.