Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T190A1ACF09052E83752E3F2D066B15B6F32D48A89CD431B0A47FD837D8BE9E80DD21695 |
|
CONTENT
ssdeep
|
48:T6y2A2BZcCCiAnA8a0I0PM50T0S0w0kB/W2qnWAePATmcAIRsM2giEOtfEIPOFuL:T6y+JCgFuKRslgikIGyhIjE4U/ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bfc48019c42bb97e |
|
VISUAL
aHash
|
7f3fbfff9a0b00ff |
|
VISUAL
dHash
|
f0d07049725a5b34 |
|
VISUAL
wHash
|
7f6e8c1c000b00ff |
|
VISUAL
colorHash
|
06c00008001 |
|
VISUAL
cropResistant
|
f0d07049725a5b34,5c7f6c6c6eeeced0,2e2e0e2e262636f1 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.