Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17F12B5732440783D02B783CEE762721DE2D7A7C2E6322985D5E4C3C94AE9E59D5A3B0D |
|
CONTENT
ssdeep
|
192:bZalZa+BZaLJHZ5xR7jOed3bk93H7bcE+n9B+6wFWLnx/hx8hhZqAGo1:x5FOQ7wFkx/hx8fZqAF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c3863c3c71333a9e |
|
VISUAL
aHash
|
007c3e6030206c2c |
|
VISUAL
dHash
|
cce4cccce4c4d8c8 |
|
VISUAL
wHash
|
067e2664707c7c7c |
|
VISUAL
colorHash
|
38003018000 |
|
VISUAL
cropResistant
|
2288771711e21582,cce4cccce4c4d8c8 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.