Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T102B2B733504D253B076349C6E275E789F396A28BC6B70A45A2ECD3CD1BEACE1ED17016 |
|
CONTENT
ssdeep
|
384:qSRZCcIIeuJ3h37y4/TVsxVTVDVxL9V6F/a+okFTPep4eSzq:qCZCcIIeuJx37vKxhxT6F/yyed+q |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b16673626362f0e3 |
|
VISUAL
aHash
|
0000ffefefcfcfcf |
|
VISUAL
dHash
|
8d32161f1f9f9b9a |
|
VISUAL
wHash
|
0083c3c3c3c7cfcf |
|
VISUAL
colorHash
|
07000000000 |
|
VISUAL
cropResistant
|
01040d0d0d8d0091,3b17171f1f939b9a,2121251515052121,909096d9d9869090 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.