Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BB6275722000B83B42A782D9AB72632FD3D2838DDD5B1A5563FE875D4ED6F80EC26156 |
|
CONTENT
ssdeep
|
384:hVQIIo58zzCC/sJb6f2OcHTAXrRLgofqVqR:hOIIl0B+rxgofqm |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc1ce3c3ccc3c398 |
|
VISUAL
aHash
|
f700800098e7e7ff |
|
VISUAL
dHash
|
49323434320c0e0c |
|
VISUAL
wHash
|
e70000009ce7ffff |
|
VISUAL
colorHash
|
07000200018 |
|
VISUAL
cropResistant
|
49323434320c0e0c |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.