Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10AA29323B648353243C742EAEF315798F36581289B83262DD6F9C24C5BC2D94DB367A7 |
|
CONTENT
ssdeep
|
384:9444xanrGXgTVtEWr43tV2oFAr9Ix6wbjgDDKOwz7w/1lxa3:9444YnrpVtJr43T2AAr9mLYDejHwtlE3 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
98b367d93244d873 |
|
VISUAL
aHash
|
00871f1f1d190000 |
|
VISUAL
dHash
|
dc0f31313933330b |
|
VISUAL
wHash
|
00ffdf9f9f1b0100 |
|
VISUAL
colorHash
|
310020001c0 |
|
VISUAL
cropResistant
|
dc0f31313933330b |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.