Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T167B2D8A5A3486D3DB05383E4DB36733E227A5296DB0A1218C6F843B85A94CCEDD375DC |
|
CONTENT
ssdeep
|
192:X3GpGzYrVoMxVuJNbUupxE02UsKnCTPSt0/uELM84hhTt0nXCm11t9QRsF0N7Wy1:vzYOM+jdpeKn10/ur/hTtXmq6GNXmFI |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9b8a6669229e98ee |
|
VISUAL
aHash
|
9d081c1c08088080 |
|
VISUAL
dHash
|
595a31b95ada3408 |
|
VISUAL
wHash
|
fddc9e1e3c29c088 |
|
VISUAL
colorHash
|
38031000000 |
|
VISUAL
cropResistant
|
595a31b95ada3408 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.