Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C063557063016E3F550386DCB167B766615792DCCBB3C3A4625E432ADB4BCE2AB326D0 |
|
CONTENT
ssdeep
|
768:917kNCoAJJQAxWciuJ5G2OjykaNcFD+6/XIid:91Qoo6JQAxWciuJY2OWkgcx+6/Xd |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d3936c3c92e661e1 |
|
VISUAL
aHash
|
187c7c3e0e007070 |
|
VISUAL
dHash
|
b0d8c8ccdc58c1c0 |
|
VISUAL
wHash
|
787e7e7e2e007070 |
|
VISUAL
colorHash
|
38200038001 |
|
VISUAL
cropResistant
|
b0d8c8ccdc58c1c0 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 193250 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)