Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C61321309140BA37409785D9AA35670FB6D2CA8ECF670F8963F593AA5FD2CB1DC1160E |
|
CONTENT
ssdeep
|
384:JjvKaPk/zABCWjnXW16i7MeTw2zlLbl2pnHYZuSby0FWywitEaV0SaSZ4rSgNp5k:oaPK4BjnXW16WMeTLgHOd6yfaNn1pQWI |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c4b5bd3192ecc136 |
|
VISUAL
aHash
|
ffc2707064600078 |
|
VISUAL
dHash
|
b60ce6c5ccc000f0 |
|
VISUAL
wHash
|
ffe2f2f0646040f8 |
|
VISUAL
colorHash
|
00000000180 |
|
VISUAL
cropResistant
|
4c4ca3a3a23232a4,a2acd2332baca082,1616163686808041,b60ce6c5ccc000f0 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.