Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19342B8B264049D3B43C7D3D6F3166726A7D38319C2932A1572FCCB6A1EC6E41FD8A429 |
|
CONTENT
ssdeep
|
192:NSMioXhFrwejXumdnmpCitRkX+kImgus9H01MWbuSoS:AMPrfumdoCYS+kIBF0yW3 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a023f918f8cbcbc9 |
|
VISUAL
aHash
|
ff00200000003fff |
|
VISUAL
dHash
|
abdfc7d7b7f6dc34 |
|
VISUAL
wHash
|
ff03330301007fff |
|
VISUAL
colorHash
|
0ec01000000 |
|
VISUAL
cropResistant
|
000b0b23238b00af,b400000024241a3a,bfcfc7c7b7b7f6dc |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.