Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D98208223A4E782D136743CF9BA1332EF1CF93D2E9255519D5E8C3A52386E52C9A3608 |
|
CONTENT
ssdeep
|
384:YwjJWMkcxJiTFNbR7MRG5qYAG50MzEKeWLiZ9JqQVMu2RfGAudh:lJycxJqFFkCqBRMZ6t6fGAuX |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e9d13073c71c38e3 |
|
VISUAL
aHash
|
40e0c1f9f9c18101 |
|
VISUAL
dHash
|
8e868363430b23ab |
|
VISUAL
wHash
|
40e1f3f9ffc1c101 |
|
VISUAL
colorHash
|
300000001c0 |
|
VISUAL
cropResistant
|
5353b50b4acaebab,8e868363430b23ab |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.