Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E3728470316216BF41D7C6E1B3A5AB2A71F8C359D22B860963FC83A65FCAC46DE03754 |
|
CONTENT
ssdeep
|
192:YwiHYZOgnCxUMxDgB9qW0wVqWtbuB/WHhaIxmI3H/fjgt60RDOLWawug8tm2PmnQ:YwiHeNnC+Mc0W5duB8NaDOLWaw61RdF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92936d6d3c9292e3 |
|
VISUAL
aHash
|
02666e4c60000000 |
|
VISUAL
dHash
|
96ccc9c9dcd029c0 |
|
VISUAL
wHash
|
7e7f7f6e6c280400 |
|
VISUAL
colorHash
|
380d0001000 |
|
VISUAL
cropResistant
|
f0c0a0e0c0e0e0e0,96ccc9c9dcd029c0 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 44 techniques to evade detection by security scanners and make reverse engineering more difficult.