Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1635312B2B0086736036346C5E31DF55C7586E305CB5B0618F6AD53B76AE6CE89C3E28E |
|
CONTENT
ssdeep
|
1536:tYY6FyvPZ2DqXGHVfFnuHQEut+EoJJMM+Z/uGa9vUobqGSlloKuFT0B:te7I80T0B |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
927b6d9296c63239 |
|
VISUAL
aHash
|
0400043e3e2c0000 |
|
VISUAL
dHash
|
69122d6c6c6d1330 |
|
VISUAL
wHash
|
a4c0bc7e3f3f0518 |
|
VISUAL
colorHash
|
38200030000 |
|
VISUAL
cropResistant
|
f0f0cc9b98dcf8f8,39686a2b2b131293,69122d6c6c6d1330 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 13 techniques to evade detection by security scanners and make reverse engineering more difficult.