Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T128135A7071A4CC3E65D722B1A7D2263B12C66BCDCA5212905BFEBA5FCDE6D94CE80C50 |
|
CONTENT
ssdeep
|
768:6msJT+tYQbb7mrMj+pkbHKjqwASF5nr2CgShc6OE4OaQODrOUXpSpdSx1J63xFNS:6msJT+tYQbb7mrMj+pkbHKjqwASF5nri |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c3c73c381c4df338 |
|
VISUAL
aHash
|
0474747c0e640000 |
|
VISUAL
dHash
|
dcc8ccc4dcccc228 |
|
VISUAL
wHash
|
2674747c7e6e00d6 |
|
VISUAL
colorHash
|
38040600010 |
|
VISUAL
cropResistant
|
dcc8ccc4dcccc228 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 1 techniques to evade detection by security scanners and make reverse engineering more difficult.