Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14C73C733D35A313B529742D8BBE6F3A47BD64159C7060B10AEFDC26857C9C49BE32A84 |
|
CONTENT
ssdeep
|
1536:AKBJYudeeKeeieeMeePeeneeKeebeeTeejeereedee+Lukw6NZunNlqhuhNDb2k0:Avc9qght2kb0FmWZj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c3b6253c3cb492e3 |
|
VISUAL
aHash
|
d7746eef003c0038 |
|
VISUAL
dHash
|
b6c9cd4de0f0c2e0 |
|
VISUAL
wHash
|
f77efeb6003c0038 |
|
VISUAL
colorHash
|
100000001c0 |
|
VISUAL
cropResistant
|
a045bae8ec9a6580,b6c9cd4de0f0c2e0 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.