Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B2447120B4963C3344A7DBE1EA251F8161C5F719C58E0281D5A843BF9FFBFA0B998764 |
|
CONTENT
ssdeep
|
1536:nA5D3+Nt9zY3Qjzl5uWmKHKtUrgz6WwDnDm1n5DJ4aiQ/2sYUSkvfF2rilLpzHxj:nBY3QY4aiX/gH5 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed2b12363c6ec9c1 |
|
VISUAL
aHash
|
8181f981c3ffffff |
|
VISUAL
dHash
|
171b63233b000e16 |
|
VISUAL
wHash
|
0181818181ffffdf |
|
VISUAL
colorHash
|
060000001c0 |
|
VISUAL
cropResistant
|
171b63233b000e16,3535ccd45425b192,2c03132d80233223,5999b9e1c1c5d4c0 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.