Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1406255F25041A93B56D3C2D6FB61233EA2C2C785CD8B1E6917EE4B0F9AD5F92CC60415 |
|
CONTENT
ssdeep
|
192:W3r/II/iSqumW9gy61puHTBjuzBnMcU9v5deXWKJu:W7/II3kf70TBjwJcDD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ce8931734cccce33 |
|
VISUAL
aHash
|
001f3f3e38b08000 |
|
VISUAL
dHash
|
d2fae2e460601020 |
|
VISUAL
wHash
|
0a7f7f7f3eb08000 |
|
VISUAL
colorHash
|
38000400038 |
|
VISUAL
cropResistant
|
d2fae2e460601020 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.