Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T133D2EB147281B83E07AB82D556A1572AE2E2F752FE23D51ED2E8C70D17D5E42DFB2308 |
|
CONTENT
ssdeep
|
384:xDcKs8+cY4ieDniS9adD03XS5I8R3PxlNWlL1iYbN5ah2zkGiAwcwxl5jo/i6:xDcKnFieDnPBS5IwNMLgsjah24GbonId |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8b3871e271d3d992 |
|
VISUAL
aHash
|
00183c1c3c3c3c00 |
|
VISUAL
dHash
|
dcf0f0f0f16168e0 |
|
VISUAL
wHash
|
00183c3d3f3f7e38 |
|
VISUAL
colorHash
|
380020000c0 |
|
VISUAL
cropResistant
|
dcf0f0f0f16168e0 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.