Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E78279306586EE3B2183C1D2D9311B0F35D2C26ADE272B0653F9479E6FDBC99CD1A609 |
|
CONTENT
ssdeep
|
384:g4hTABMaJBDwmiiiyOUAADFEHzxLiPlbdiMBP07Fdn20EIp/2b1t6pfomLfXTbur:g4hTABMaJBDwmiiiyLAADFEHzxLiPlbJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ba136cc42e3c966d |
|
VISUAL
aHash
|
00000400ffffdbd3 |
|
VISUAL
dHash
|
d4c9c8699b003323 |
|
VISUAL
wHash
|
00000004fffffff7 |
|
VISUAL
colorHash
|
33c01008000 |
|
VISUAL
cropResistant
|
f391b5b3955352e0,c01018133333332b,9ada28a9b6b2b232,9d79fafaf3e1c4d4,d4bccdc8c8e8e99b,011d0d1b1b1b33b3,9b8d96668cd958d0,430e8e8ae6eedac2 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)