Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16962B632A140B16F158303C6CB307B1DE29C41E2E5A21A296BFDC7D6CF83E56DC23A95 |
|
CONTENT
ssdeep
|
192:OtDRn1iQtS+rn+Anenlnb9zEvhrNbCxev9nYgv/P3WIvyJGZj:Y1O+z5GFRAvxNbCxevd1v/+Iv2e |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b2c9cdc963328ccd |
|
VISUAL
aHash
|
fbff87c7c7c7c7df |
|
VISUAL
dHash
|
2b062c0d0c2c0c36 |
|
VISUAL
wHash
|
f983878787878783 |
|
VISUAL
colorHash
|
072000000c0 |
|
VISUAL
cropResistant
|
2b062c0d0c2c0c36,02126d95926bbeb4,926a699422500b43 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.