Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12F730974A155037F629781F4BBB1DF99D089E349C7338A45E3FD12A62EC6C92EC63284 |
|
CONTENT
ssdeep
|
1536:coSK7lOUCseb7eU2RyRLLCyHHgidMCCeb7eU2RyRLLxYKbO4NrI6yXoSnrI641CY:nT2LFLDNrI6yVnrI647+zPF4prLjNyuJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ff4f545a521644b1 |
|
VISUAL
aHash
|
00808381c9d1cfff |
|
VISUAL
dHash
|
0c2a631b0b233e1c |
|
VISUAL
wHash
|
0081a3a1c9f1cfff |
|
VISUAL
colorHash
|
03003208000 |
|
VISUAL
cropResistant
|
2a23530b0b233e9c,e4ecececcc52e6f6,9c68d984a4ccd0f0,dc8ca2929ec89219,2089c7b0a0a0c2a4,1c2a235b0b2b271e |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.