Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16322D8012886BD0D939753CFE6B34A25DF8F9741E723A96CDDD7CA0E2298A25C17D208 |
|
CONTENT
ssdeep
|
192:f1eLMvK8MBbSph2w8D0Gqea+Ep5GSGum6:JK8MUF8QfpLUum6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bf32c0cc1f323e8c |
|
VISUAL
aHash
|
ffff07070f1fffff |
|
VISUAL
dHash
|
c4906d6d7c348840 |
|
VISUAL
wHash
|
4ccc07070c0cfcfc |
|
VISUAL
colorHash
|
0e0020001c0 |
|
VISUAL
cropResistant
|
c4906d6d7c348840,c8c0c920c204040c,a82828b6353535ce |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.