Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EEC2323432515ABB64C7C3F27764EB2BA2D8C74BD927CA89B3E4C25A6BC7C528D41341 |
|
CONTENT
ssdeep
|
384:p9Hhl09R5XiBb3xaJBkqQUIhE4T8nAJGY57KkbM39sxS:p9Bqn5QDcMNhE4T8nAJGY57KkbM39sxS |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ba39c2ce1a3969c3 |
|
VISUAL
aHash
|
fdf78387f7ffffe7 |
|
VISUAL
dHash
|
69261b3c24330c4c |
|
VISUAL
wHash
|
ad87818386e7e7c0 |
|
VISUAL
colorHash
|
07600000600 |
|
VISUAL
cropResistant
|
69261b3c24330c4c,4c4c490f0dcd4f06 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.