Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T121828676A764963A0B6342E919F81F8FA750C3C4D5D31A83D5E8C7EC6AD3CE4C9224B1 |
|
CONTENT
ssdeep
|
384:j1OA+Dck8iDqQv1Hq5SOsUSjFqn6L13R/D:PkcpQv1KcOsLjFqn6TD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a40ecaf0f05acee5 |
|
VISUAL
aHash
|
00000003c3c3c3c3 |
|
VISUAL
dHash
|
1761618616969696 |
|
VISUAL
wHash
|
fb0010c3e3e3e3e3 |
|
VISUAL
colorHash
|
12001008180 |
|
VISUAL
cropResistant
|
c000120c2c2c1200,0000808080808080,0202020202020202,8080808080808080,1761618616969696 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.