Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DF4262306194ED3F90C382D49635AB5F32A6D286CB47030596FD83AC9EC6DEBEC27149 |
|
CONTENT
ssdeep
|
192:JIX2KqK8ermgChjN6aD2I5wLURsauYIueHe7:BKqK8amgmjAaD2I5wLURsXue+7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
99b166e0e2d9d0d9 |
|
VISUAL
aHash
|
ff08181818181800 |
|
VISUAL
dHash
|
8e33b2b2b2b2b3cd |
|
VISUAL
wHash
|
ff1c1c1c3c1c3c3c |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
01929aca9a22151e,71dcdcdcd4d4d401,4c32b2b2b2b2b3cd,60616169696b6161,bce49cf4aaccd001 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.