Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17E82DDF295569D3741F3D1D6A2BA273B62E28288E99B071593FD875D0BCEE40FC12812 |
|
CONTENT
ssdeep
|
192:yKO7NpU3ok0blF/wU+jF/F/VI/MU1/B26NHv/ycFEl9e77FLvBDI77FLvBDaBdBA:yKm5TRFQF99IkU1NZvTFs+3kFI572q+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ecec13929365693c |
|
VISUAL
aHash
|
ffd1d1f1ffffc181 |
|
VISUAL
dHash
|
382323e3233c2727 |
|
VISUAL
wHash
|
9fd191f19f878181 |
|
VISUAL
colorHash
|
0e000000c00 |
|
VISUAL
cropResistant
|
382323e3233c2727,2330415551494131,0041252525c10202,4f4e464f56564f4f,04da393939fb5a2c |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.