Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18F432E319145E93B40A383E593399B6BB3D1E64ACB534605A7F8C38D8FEBC51DD32298 |
|
CONTENT
ssdeep
|
768:R444bSoxFCk8OwGk48OwGHI8un88u0y8ood8oMXWn5Nfw8u7+8uHh8ucxJWjvZsE:R444bSoxFCmWnsJWr5MvL5U+AwM |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9129ec35e3661e66 |
|
VISUAL
aHash
|
131e0008080cffff |
|
VISUAL
dHash
|
a6b2f0d8d8b8b4ed |
|
VISUAL
wHash
|
531e000c2c0effff |
|
VISUAL
colorHash
|
120020000c0 |
|
VISUAL
cropResistant
|
a6b2b6b6b230b8b2,9aaa96969658a6a2,b63cb40000961696,e5a4edcd2d830002,84d4c4a6aeb2b6b6,216d89991a16e529,b0b0d8d8d0d838b6,26d6e5a4a4cd2d2d |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 11 techniques to evade detection by security scanners and make reverse engineering more difficult.