Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14253D6F1A1F166BA014FB3D4E2257B29729392F6DB864BE182D4DFC45F86C08DC6B484 |
|
CONTENT
ssdeep
|
768:l/QgfXWUJpwEKaF6y6IWXvz5fZywkNLLXcpX4McOdllXQD4L92ypt:l/Qgvd6y6t/VQwkZSlXQDWoe |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b83ac747324e4b39 |
|
VISUAL
aHash
|
00cf8187cfffffff |
|
VISUAL
dHash
|
691b1b3b1a9363b0 |
|
VISUAL
wHash
|
0083818783cbfbff |
|
VISUAL
colorHash
|
07040001600 |
|
VISUAL
cropResistant
|
691a1b1a1a1363b0,1629496969690912,03e3031d7b3f3833,b8ac9de9cdcd473f |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.