Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CF92742212841D3F175783F8E5A1F628E295C2D4DE279F17F2AC42661B8ED69DC232DC |
|
CONTENT
ssdeep
|
384:l2tv6BKEFzWvUIpPBr2BOHnctLhuP1R4rlK4AyNNDclPg4aKhdF96+nHe4T6Ge/5:l2tvWKEFzWvU2JyBOHnctNudR4A4AyN/ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc3436319dcccc76 |
|
VISUAL
aHash
|
6600381818183c3c |
|
VISUAL
dHash
|
d40d30b230707070 |
|
VISUAL
wHash
|
7e003c3c3c3c3c7e |
|
VISUAL
colorHash
|
38000e00010 |
|
VISUAL
cropResistant
|
d40d30b230707070 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.