Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AF6274BA60446D3B03B7D2D9BA10337ED393858DC5861905B7B98B0F8EE2F81CC5A957 |
|
CONTENT
ssdeep
|
192:EmHCwkHJzJ44iF00folnXVbASEjKT4fIAn:ZBkn44uf6nXVci8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9c77760c93667611 |
|
VISUAL
aHash
|
0081031f1f1f1f1f |
|
VISUAL
dHash
|
5c3f3f71f3b3f7ff |
|
VISUAL
wHash
|
0481831f1f1f1f3f |
|
VISUAL
colorHash
|
000002c0010 |
|
VISUAL
cropResistant
|
6545d5233326d4d1,2020ccc9e3b3b6b4,5c3f3f71f3b3f7ff |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.