Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16F72317149A6A93302E381D2EB3647AFB3E28148C6531A46D3F8C34D6FDED55EE13059 |
|
CONTENT
ssdeep
|
384:je2Ii9eXIHNLIYON7/B5I6GIIRvXffXMrm0MimqetAn:joV42Tjg6GVxXMrm0aqetk |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9c96b636361496b6 |
|
VISUAL
aHash
|
66ffff1818180000 |
|
VISUAL
dHash
|
d433703030301010 |
|
VISUAL
wHash
|
ffffff1818181800 |
|
VISUAL
colorHash
|
38c00018000 |
|
VISUAL
cropResistant
|
d433703030301010 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.