Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A91229B5D2B7927B14B2C2D2A6EA67BB60F4204DF55312A4A2FD833C03DDD02B573A51 |
|
CONTENT
ssdeep
|
192:Gtdr94QOgXCsHr657FtqxhQZMSCsHr657FtqxhQZM2mhGQd6R:HgXCsHr657FtqxhQZMSCsHr657FtqxhG |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b3664c5d4c59734c |
|
VISUAL
aHash
|
00e7e7e7ffffffff |
|
VISUAL
dHash
|
324d4d4d2a585a48 |
|
VISUAL
wHash
|
00c3c0c0002c0c04 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
4d4d4d4d2a5a5a48,00002c3032320c10,c8f4f6edeae9d4d6 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.