Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1118210B260047437019B83DAB630637EA3B28A85DD5B2A0663FD874D5EC7E85EF1750B |
|
CONTENT
ssdeep
|
384:oNGIIobDNucyJuFolN7vag2AwoLN2EUQlEsCZZJFIqoP:ooIIrcyAS5hN2EUQvAZ6P |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8a43717c77cb4962 |
|
VISUAL
aHash
|
00073f3f0f1f1f1f |
|
VISUAL
dHash
|
dffff1f9fff7ffff |
|
VISUAL
wHash
|
00031f3f1f1f1f0f |
|
VISUAL
colorHash
|
000003c0000 |
|
VISUAL
cropResistant
|
6d498a75776765d5,dffff1f9fff7ffff |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.