Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1610331789210DD779093C6D8E636A36F72A1E288EF43035193ED832C86E6DD6ED1563C |
|
CONTENT
ssdeep
|
384:84HjYuHy6eQ0jcWJjF9DUNPw9lttEnlCmL4sy6c3rW9oIAUrHuoUXkQnhTyxhTV:84Ul6c3a+MHuoU563 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b54a0fa5e0be0fa1 |
|
VISUAL
aHash
|
010080c0c3830303 |
|
VISUAL
dHash
|
23d02e14962626c2 |
|
VISUAL
wHash
|
f500c6e7e7c70703 |
|
VISUAL
colorHash
|
380000001c0 |
|
VISUAL
cropResistant
|
23d02e14962626c2 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 1 techniques to evade detection by security scanners and make reverse engineering more difficult.