Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C52123A252154A3E45A1A1D0EFC9E1069635C2C2D8151901BBDE87CE1AC6F1CFEE3250 |
|
CONTENT
ssdeep
|
12:hFTMy7FU3zq4+zqMqqA9quPqJbpGbXkfx5KbF0H9R3yv3H9sTyI3cWgEWA04M03C:hWCuzody97PWcbyx5HByeWA0sC |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
800091bf7f7e6ccc |
|
VISUAL
aHash
|
007f7000ffffffff |
|
VISUAL
dHash
|
24c0c525f8000000 |
|
VISUAL
wHash
|
0030300010f0f0f0 |
|
VISUAL
colorHash
|
06000003006 |
|
VISUAL
cropResistant
|
c0c4c4c4ccc52585,6000400000000000,0000c02020008000,01010d3131110911,0000080808080000 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)