Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16153FE331305592869B75DED7A71AE93A0B5F29CD603F0ACD39E41E04BE3C2BE51264B |
|
CONTENT
ssdeep
|
768:am2kaNlY8HoT4UGqsjTooXsKOTZz+iMEO4Vj/Q+W9:am2kglYD+TooXsrT6Z9 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ccd8e33263da4798 |
|
VISUAL
aHash
|
4058fc3c00005e7f |
|
VISUAL
dHash
|
8894f0f0b068b0d4 |
|
VISUAL
wHash
|
4078fc7c0000ffff |
|
VISUAL
colorHash
|
18000000038 |
|
VISUAL
cropResistant
|
d0ae8eb6b68eaad4,8894f0f0b068b0d4 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.