Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A1728B979234DA7F8087924CC3139124E2FD61DFFA94E720B2BECB9F49645939C16B90 |
|
CONTENT
ssdeep
|
192:rg03sekggDkNE+AI+tBAsfRsPetZR3v49hXu:rx3sek7/pBBAsfRsP8Z5v49Fu |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8855aa7577a255aa |
|
VISUAL
aHash
|
1818180018181311 |
|
VISUAL
dHash
|
3232323230332323 |
|
VISUAL
wHash
|
183c3c183c181b1b |
|
VISUAL
colorHash
|
30c00018000 |
|
VISUAL
cropResistant
|
00000a969e0a0000,56475b57464b3936,3232323230332323 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.