Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18DC29632A1C8541B418A83D2B790BB6BDBD5C448EF634F04E5D68FCEE9D5E90F8B2419 |
|
CONTENT
ssdeep
|
768:lmY3nriMok+K6PxqP9o6KMdGN6nN96mgEmChwfoZ1o+AzfV:8Y3rink+K6EKXNm6mf/0+q |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed1313c6926d6939 |
|
VISUAL
aHash
|
00cfc3f3f3f3f3c3 |
|
VISUAL
dHash
|
631e13272727272f |
|
VISUAL
wHash
|
00ff81f1f1f1c383 |
|
VISUAL
colorHash
|
070010001c0 |
|
VISUAL
cropResistant
|
030b232b6b230b03,1e1b27272727272f,72687068686868fa,a28080b211d280b2,04b033d4d4303008,19c685c6c6c580a5,7d7fff3b3bfd7fae |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.