Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18A93DD32D440223B51A361DAD67DDB73F7E0C88EC3861E42C5EAC26E8B59D909973D2D |
|
CONTENT
ssdeep
|
1536:+444GIVqljceVsYwFTIAjLFuQU1bCQ7vH6rYHIacPbvH6rY2:IcLFQqb0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b83847c7c68eacc6 |
|
VISUAL
aHash
|
00828f8ffffbffff |
|
VISUAL
dHash
|
3a1e3e3cd696540a |
|
VISUAL
wHash
|
00008f8bf3c3ffc7 |
|
VISUAL
colorHash
|
07000038001 |
|
VISUAL
cropResistant
|
222c232b2b3220c0,1a3a3e1886964c0e,67e3d3c9ade6d0e1,181a3e1a3a383e3c |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.