Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11A6295B33191B53B017782C77663233DA1F6428DDB8A0615A7ED0B2D8DCBE80FC1649A |
|
CONTENT
ssdeep
|
192:jWS44vW9oSPlDvW/PNczUX4VmCpaW3ezY3xZkVlKuz0z:SS44u9oSPlDaPSzUX4VJp/ezYDkVlnoz |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8f28717371ccc671 |
|
VISUAL
aHash
|
000b3b3b3e343c18 |
|
VISUAL
dHash
|
dff3e2f2e464d8f0 |
|
VISUAL
wHash
|
00033f3f3e3e3c3c |
|
VISUAL
colorHash
|
10007000000 |
|
VISUAL
cropResistant
|
0088532b37940900,dff3e2f2e464d8f0 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.