Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18933443112922B3BE55B8BB5F160737953A9C75DDBE3C225A29E432397C7CD24F22284 |
|
CONTENT
ssdeep
|
768:nGtBBwu3iYj4z14PjtKYeA1id2bcoC/pAIbMtqh+6/XIid:GtjwuSYjG1/7RTbMtqh+6/Xd |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cb9b6161cbcec464 |
|
VISUAL
aHash
|
481c3c3c3c180018 |
|
VISUAL
dHash
|
d9f8f069f07120d0 |
|
VISUAL
wHash
|
783c7e3e3c3c007c |
|
VISUAL
colorHash
|
300000001c0 |
|
VISUAL
cropResistant
|
8c19594b4a0b4ad2,d9f8f069f07120d0 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 193252 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)