Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19C0364374323ED5611B1C0DEE5771F4D928A830ED2079B8093A982FD72C6D95E962BCE |
|
CONTENT
ssdeep
|
384:33G/QJ7ded1XP2lc+BGn6/ZoRMFJUhBGqTWqUA8Jbafas5A6YMz:33G/QJ7w1elc+2GZoRMFaGJy8Jba+3C |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ea6a56b539928c4d |
|
VISUAL
aHash
|
e0e0f0c9f9ffffff |
|
VISUAL
dHash
|
0903333b23430c03 |
|
VISUAL
wHash
|
e0e0908189ffefc3 |
|
VISUAL
colorHash
|
06006000000 |
|
VISUAL
cropResistant
|
0903333b23430c03,004d0d1f0b4b4e0c,0000303030040000 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.