Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EFE31F73615C14BD23730AC2B258671E78C6A00FCD5A49C6E2BB82EC53F5DD12662BDB |
|
CONTENT
ssdeep
|
3072:GSnnwwEAFvZj/i8ZQ0Ki//og0QX/GST7A5S:GSnnwwEp8ZQ0Ki//h0QX+STSS |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e91e974964b64b4a |
|
VISUAL
aHash
|
fffbf9f1f0f9ffff |
|
VISUAL
dHash
|
647b6333f3533a4c |
|
VISUAL
wHash
|
bff910003030ffe7 |
|
VISUAL
colorHash
|
07402000041 |
|
VISUAL
cropResistant
|
647b6333f3533a4c,13392bc3868d9c1c,969ae6eb4e5e9e96 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.