Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C5F253725184593B02A793D5727AB71FB2D3BA4DDE130A0AA2F8878C8FC5F95DC3144A |
|
CONTENT
ssdeep
|
384:gRnJII8iF6JZymaTHX9dfo1ru2XwTU5WV/4GZlq24Vj0g99t9lG0Sjz3TIR3q5:gvII8LzRaDXbQ1VieWRzZlGN0gtTSvWs |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c7cfb4383861956c |
|
VISUAL
aHash
|
823c3c20103e2036 |
|
VISUAL
dHash
|
5a60404961f0e86c |
|
VISUAL
wHash
|
8f3e3c38383f203e |
|
VISUAL
colorHash
|
30007000080 |
|
VISUAL
cropResistant
|
5a60404961f0e86c |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.