Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T137445660A144FA3F70FBE3E9C774A7DB329AF1A8DE8516A597FCA35416C1CE5EA01010 |
|
CONTENT
ssdeep
|
6144:UeL5dL5V2L5w9L5rL5zL5vWL5I2L5xmL5RIL5QRL5TlL5i8L5tlL56L5IbL5YCLT:L |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bcd2cb869666cb84 |
|
VISUAL
aHash
|
ffc38181c3c3c381 |
|
VISUAL
dHash
|
40333b2b3f2b2b3b |
|
VISUAL
wHash
|
ffc38181c381ff81 |
|
VISUAL
colorHash
|
17200000088 |
|
VISUAL
cropResistant
|
40333b2b3f2b2b3b,1930aa4c34743717,650164e496e60145,f1f1d1948d8fcfcf,737169cad2b1e8cc,e9f3f9f8dbc6cccc,f7b3737b676cdcd0 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.