Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C363F8B523842179A2174BE8F331B779B2A751EDDB139044C7E447A0EBD18ECEC62AC5 |
|
CONTENT
ssdeep
|
768:AbYck66leLLf+bXjZPhikvNtAE8tgQbWoW72ExmEhtgtak66Xu9Im89cU:AbY5GvmXNEyT6w/hCtPQCmfU |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
835a2d2ce31ad3c7 |
|
VISUAL
aHash
|
01006c2d61031f6f |
|
VISUAL
dHash
|
3349c9c9cb37f7cf |
|
VISUAL
wHash
|
81047c0d7f031f7f |
|
VISUAL
colorHash
|
38000000180 |
|
VISUAL
cropResistant
|
f3c424a5dbc8d8e2,a2822967531ba4b2,f0e6c2c5a5868140,3349c9c9cb37f7cf |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.