Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1239252B720016D375193D2EEBA30132AA3E18A88C99B1A45B3FDC70E4DD3DD5DD19A1B |
|
CONTENT
ssdeep
|
192:9mf8kBtvaL44Pyvrg3dVY7e1FSzP7z/LTJMRGpAKkUqZjWOGzT19NiCyRoXL:YHu44aDg3rh1FSb776M6KmjWOMB |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
87c0f8b8f8ccc6c6 |
|
VISUAL
aHash
|
ff003f3f0f0f0f3f |
|
VISUAL
dHash
|
bfffe7f3ffffffff |
|
VISUAL
wHash
|
ff00311f07070f3f |
|
VISUAL
colorHash
|
00600030000 |
|
VISUAL
cropResistant
|
005b2b2d29db21ff,64643486ccd1b7b5,54757a676a4afffb,7e7aee5ed6ae6efe,ffffffffffffffff,ffffe7f3ffffffff |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.