Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17FC2A34121C0537E0E90021A67257FDFE3E641F8F7B229A434EFCA5BD965AA6C4339C6 |
|
CONTENT
ssdeep
|
384:8hmbgf6i82BtR4+bI4+dUN1Q7Tsro9c15k:dgiYtRbM2g7YiMk |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc0d09034f1ebeec |
|
VISUAL
aHash
|
0000ffffffffffff |
|
VISUAL
dHash
|
f31b2e383438303c |
|
VISUAL
wHash
|
0000838f9f8f9fdf |
|
VISUAL
colorHash
|
07000030000 |
|
VISUAL
cropResistant
|
1b2f3826383c303c,cff3b3cfb3f3d1dd |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.