Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BAE285778316DA66017380FCA12B5E9C93494709D65B8700E3AE82FD77C6954ED237CD |
|
CONTENT
ssdeep
|
384:31wASkbcAO81rFVzosoX4Jqu+yMkmQb2jBQszDatYEe12muedRP/XlHNbsp5op:31wAF/OYBVzoso4AuGkC12muedJ/u6p |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e976966d32498c96 |
|
VISUAL
aHash
|
e0f0f1f9d1f9f9ff |
|
VISUAL
dHash
|
4905231333131308 |
|
VISUAL
wHash
|
e0e080c181f9f9ff |
|
VISUAL
colorHash
|
07400030000 |
|
VISUAL
cropResistant
|
4905231333131308,1386f8c6d621822b,9486032b6969010d |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.