Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1580286C352C1217D03B247CEBE327FADD36A118876841E6B64DD469C99E9B416C33E87 |
|
CONTENT
ssdeep
|
192:f3YgTtjis+67r6ULYNNWseuR63/z8J5dezbY:f3rpjtD6UcNN7e66vYVe4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c49931696b1b6d33 |
|
VISUAL
aHash
|
383e3c3e30383c3c |
|
VISUAL
dHash
|
e0e0e0e0e4e0e0e0 |
|
VISUAL
wHash
|
387e3c3e30383e78 |
|
VISUAL
colorHash
|
38006000000 |
|
VISUAL
cropResistant
|
e0e0e0e0e4e0e0e0 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.