Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10AD2753662497C3FD56B86CDD316F3AE305BB1CACA5B0604A6E01329DB84ED7FC25258 |
|
CONTENT
ssdeep
|
384:yIyNyunqSQ4HMQvpbg+a6skkUYNDFuA1CmKtxXg7XH+f1RfWKTA8:TsyuqSXi6skkUy4AWtxXgz+/tTA8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bd69a042160f7bb6 |
|
VISUAL
aHash
|
01c38b0304e01707 |
|
VISUAL
dHash
|
739237324c40962e |
|
VISUAL
wHash
|
01d39f1786e05f87 |
|
VISUAL
colorHash
|
30001248008 |
|
VISUAL
cropResistant
|
8200204d4d4c3088,739237324c40962e |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.