Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19BB2F9B3A1446537029343C6B7727F5DA3A48280D397061195FF834C97EAD92EE33B9A |
|
CONTENT
ssdeep
|
384:8EifK3sntVCpL3VpT1fGhDCZ7kO7iP3x31SkPC1:8EifMppBjw+1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ce31ce31c6c631cd |
|
VISUAL
aHash
|
001800343c243838 |
|
VISUAL
dHash
|
ccf0f0ccc4dc6462 |
|
VISUAL
wHash
|
203c107e7e7e7c38 |
|
VISUAL
colorHash
|
38200008080 |
|
VISUAL
cropResistant
|
c800c2d3f3028023,97c4d48055555555,ccf0f0ccc4dc6462 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.