Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19D3232B250047D3F81D7D3C9B723232EA3938345CA570A176BF94B4E9AE3E51EC26459 |
|
CONTENT
ssdeep
|
192:y9HYI64HTwXCf44vqTl9EXKxrDxrZlKJo9toPqJ4a50bSecDj2pSB:y9HYI6Kv44yLEXKxXxrZg29t0qeiO0Dd |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c3a93c53c3c3ccc6 |
|
VISUAL
aHash
|
6001717c7c642000 |
|
VISUAL
dHash
|
d033c3c9c9c94220 |
|
VISUAL
wHash
|
7a03776d7c7ce080 |
|
VISUAL
colorHash
|
380000001c0 |
|
VISUAL
cropResistant
|
d033c3c9c9c94220 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.