Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14404E8A0E1C1B93B904742D4637A7F5F646FE1A9CB010F94D6B093A9A6D2CC27D232DD |
|
CONTENT
ssdeep
|
1536:xavxj1o5pQXbD1O5pQyx9Xj0JvSF6GKBCQSc7JS+e75nZjzWZG2x5VVrJ0JQciwx:xavo5pulO5pxnObVVN0Scn5h |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b502eaca4de5f292 |
|
VISUAL
aHash
|
000007021fffffff |
|
VISUAL
dHash
|
959aced6fc070e2b |
|
VISUAL
wHash
|
000007020fffffff |
|
VISUAL
colorHash
|
060000001c0 |
|
VISUAL
cropResistant
|
959aced6fc070e2b,88709598989562fe |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.