Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EC5233B72040793B42D7C3EAAB31237EE3D28286C686161263FDC75D5AE2E51DC1651B |
|
CONTENT
ssdeep
|
192:OTW98+NNo2Y44r8fOZbJ+YuU68vaoIrp5aA8zbC:Oip244L7euaoIrp5D |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8c33746c998e6379 |
|
VISUAL
aHash
|
00013f3f19383800 |
|
VISUAL
dHash
|
5a1f7b69b3e0e0e0 |
|
VISUAL
wHash
|
00033f3f1f3e3c3c |
|
VISUAL
colorHash
|
300000001c0 |
|
VISUAL
cropResistant
|
6a23f14c36a66cc7,5a1f7b69b3e0e0e0 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.