Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FA3240366004763703E392E6FB72576F73E1C286CA160B5112F8C78E8FD2D98ED9215A |
|
CONTENT
ssdeep
|
192:RIw7Zi2I1NN9xH3uXgbNOsaozuD8pTVHpJdMp99sDzZ4dgmeBGKQeb3L8:RIw7Zi2I1NzxH3UgbwhN9sqg1BGKXjL8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c353ac24359b3bc6 |
|
VISUAL
aHash
|
02707c6c66023f3f |
|
VISUAL
dHash
|
16e5c9d8c486f1f1 |
|
VISUAL
wHash
|
02707c6866027fff |
|
VISUAL
colorHash
|
38006000040 |
|
VISUAL
cropResistant
|
16e5c9d8c486f1f1 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.