Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1120293AB0A04351E5395D3CEE763B62CCF8B5206DE615E66A1AFCF1E2DC0E10CD63225 |
|
CONTENT
ssdeep
|
96:3nN8D72D7Oqmdj6qoXh3L6RMuWiAngEZMDx46C6TUlX:iD72D7Oqaj6qopOOXiAvutRtIlX |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e363c9c94b62c9c9 |
|
VISUAL
aHash
|
99c3e7e7ffffffff |
|
VISUAL
dHash
|
2b4c0c4df0aaaaa8 |
|
VISUAL
wHash
|
000200007f5b7f5f |
|
VISUAL
colorHash
|
07e00000000 |
|
VISUAL
cropResistant
|
2b4c0c4df0aaaaa8 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.