Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17F9295342406BB3F15A3A2E76322631FB1DAC14AE5572785A3F2C36A57C3F19EC63509 |
|
CONTENT
ssdeep
|
384:ubgAg6S/c4br+wSgsuaNrObNHiEnKmwh+Y8KCJKNqOKIbdKgCF:XAgovgsNqQu0ofp8TKgCF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f37a05c97092a65d |
|
VISUAL
aHash
|
008086ce80ffff00 |
|
VISUAL
dHash
|
8c0a1c1c1acfc8c0 |
|
VISUAL
wHash
|
40c8cfcfc0ff7e00 |
|
VISUAL
colorHash
|
39000030000 |
|
VISUAL
cropResistant
|
fffbcfcdcddfffff,9884391cdc1818f2,0284c8c0d8641012 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 1 techniques to evade detection by security scanners and make reverse engineering more difficult.