Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T194723FB6A105293F43AB92D76B20237A93A352C6C5C61A0676EC8B1BCDD3FC1ED13517 |
|
CONTENT
ssdeep
|
192:JULRfa02dIIDRx0XzZypUC5Qi7mFz+yzMpzr+h+Z04ZOooVA4xJW/QIx+:6ZuIIeZSUC6i7mFayzMp2h+Z0RBVds+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c7463a399ce666c1 |
|
VISUAL
aHash
|
0020707a7e666000 |
|
VISUAL
dHash
|
30c8c4e4d2cecc24 |
|
VISUAL
wHash
|
0060f0ff7f7f6600 |
|
VISUAL
colorHash
|
38002000007 |
|
VISUAL
cropResistant
|
29495d2a25a5b235,30c8c4e4d2cecc24 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.