Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AB02EAD27085CD3761A302CFE6C2D31DA3E2C599CBC66AD5E5E50BB859FACF4B101246 |
|
CONTENT
ssdeep
|
96:KC6aly0Il3pfmJj27i/kFDZBDWgB8VsXya8t2bS4rllSb:EX1pfx7i/kFvDWQOklSb |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8c63736171697175 |
|
VISUAL
aHash
|
181c1818181c1c1c |
|
VISUAL
dHash
|
ebebf3f3f3f3f3f3 |
|
VISUAL
wHash
|
183c3c3c3c3c3d3d |
|
VISUAL
colorHash
|
02000400038 |
|
VISUAL
cropResistant
|
cc8e968eaa968eae,54aa55aa54a851a2,ebebf3f3f3f3f3f3 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.