Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T110D2FF58314E9DAB047BDAE055A30E0236D8F344E11217928AEE57FD9EC7C74FCA7688 |
|
CONTENT
ssdeep
|
384:As5ve4JxBHBDp6TWfMB/63j7/ve4JxBHBDp6TWfMB/63KdLN2vZB7k:F7hVpAWfMB/Af7hVpAWfMB/AKPsn7k |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8f396ccfc5319292 |
|
VISUAL
aHash
|
183c0c003c3c1838 |
|
VISUAL
dHash
|
7471695269696260 |
|
VISUAL
wHash
|
1c3c1c3c3e3e3c3c |
|
VISUAL
colorHash
|
38200030000 |
|
VISUAL
cropResistant
|
00100c4d0d000000,7471695269696260 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.