Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17992C62A503C6A37466386D9BBE1A70B6783835CCB231B4071F4DBDA4BD3D69CD0068B |
|
CONTENT
ssdeep
|
384:BTKwKTJBwCam0fLn16LOZFO4aYy7Sh8TKLS8/J9jnvIME2yZhxtzT/J9st:BvKgCx0MQ5aYy3KLbJ5IqAhzzzJy |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec6c9393936c6d41 |
|
VISUAL
aHash
|
ffd1d191ffffffff |
|
VISUAL
dHash
|
39272327384f0e27 |
|
VISUAL
wHash
|
dd80809091e7ffab |
|
VISUAL
colorHash
|
070020000c0 |
|
VISUAL
cropResistant
|
39272327384f0e27,1b18061676e62473 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 38 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)