Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CC0286B160019C3B0277A3C6EFB1972AF1D751AEC6235A88E6EDD3CC97DAC51E913412 |
|
CONTENT
ssdeep
|
96:1I71TxGry87nNjREAiZ0vaS/AEbsn3OUjA9dJntb9t2m1uLV41p3PV4UXRV+PB7O:14ILviZ0PDbs3OUs9ftNP36mjsPI/ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dee363e3d29c1414 |
|
VISUAL
aHash
|
e1e11c1c1c1c1c10 |
|
VISUAL
dHash
|
4343303030303034 |
|
VISUAL
wHash
|
e1e19c1e1e1c1c1c |
|
VISUAL
colorHash
|
38007000000 |
|
VISUAL
cropResistant
|
4343303030303034 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.