Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10392A87081D76F37C4A7C5D4A1B5172A23E08E4DCFF30A605AAF935BDACBDA1AB02145 |
|
CONTENT
ssdeep
|
192:gLCl+wWxfaVMj3h5+0PMSWYJRTf1Z4v+bA+7Xly+38ZC+0K4AxXI3RSfd:GCl+rjz+0PBTlcIXI+3KDbXIid |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
96293c6e78b66932 |
|
VISUAL
aHash
|
013f2c3c3c3c3e1c |
|
VISUAL
dHash
|
47c1d9746c4c4c5c |
|
VISUAL
wHash
|
813f3c3c3c3c3c3c |
|
VISUAL
colorHash
|
380020004c0 |
|
VISUAL
cropResistant
|
47c1d9746c4c4c5c |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 193215 techniques to evade detection by security scanners and make reverse engineering more difficult.