Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AC128AB46261882706F7D3D05E645B7E31C4A34CEE8649D012FCC79EAF97C89DC6346A |
|
CONTENT
ssdeep
|
192:CcPpW66KA+3G0cmA+3G0cXu9u0Y7Bt/1OVv:npW66KA+3G0cmA+3G0cXuo0YV51O5 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c6ec39396db06c86 |
|
VISUAL
aHash
|
8134b4b4b0300c00 |
|
VISUAL
dHash
|
1769696969686968 |
|
VISUAL
wHash
|
81bdfdfcf0b03c00 |
|
VISUAL
colorHash
|
38001000180 |
|
VISUAL
cropResistant
|
1769696969686968 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2312 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)