Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DA92655B6185F7210287239ED71AABDEE3634004C976972C46EAC10FF4C28B1CE676DB |
|
CONTENT
ssdeep
|
384:X5XEzgKdmA4lMpjsNQtza+VaKv6kgzfFKiBBqjR:J0zgMmA4KjsN4zgQR |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b1315b4e4e4e3333 |
|
VISUAL
aHash
|
00cfc7efffefffcf |
|
VISUAL
dHash
|
c41c9a9e969e2698 |
|
VISUAL
wHash
|
00c3c7c3c3c3c7cf |
|
VISUAL
colorHash
|
07007000000 |
|
VISUAL
cropResistant
|
969a9a869e9e2698,000004c0c0040000,2234246864747cd2 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.