Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E9E3B9B4315156BF1147C7F0B235998BB24EA358CF13DA59B3E8829A6FC6CE1CD412E8 |
|
CONTENT
ssdeep
|
1536:P7lj2iIa6U3d+Ejn7ljGiIa6U3d+EjP7ljGiIa6U3d+Ejt:PIa6UtrbIa6UtrjIa6Utrt |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
966d94b66d966134 |
|
VISUAL
aHash
|
46183c3c002e3e30 |
|
VISUAL
dHash
|
c433d4d4d3ccccd4 |
|
VISUAL
wHash
|
46187e3c006e7e7e |
|
VISUAL
colorHash
|
38000007000 |
|
VISUAL
cropResistant
|
cdecd85a6828b899,c433d4d4d3ccccd4 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.