Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EFD1DD314089ADA308B9B2E497761F4AB790C304C9278F8A23F8DB4E6FC7D49CD17452 |
|
CONTENT
ssdeep
|
96:CUsFCskuSRhYHYq4j837qaam2LggYQaTopOdEvKyYFz6r:CJCskrgaj8hkggYQcop2EvKzF4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e4ec1b1b923636c3 |
|
VISUAL
aHash
|
fffff7f7ff000000 |
|
VISUAL
dHash
|
392227250732d4d4 |
|
VISUAL
wHash
|
fff3d3d7f7000000 |
|
VISUAL
colorHash
|
060010001c0 |
|
VISUAL
cropResistant
|
2338022725250412,0c3032302aa49402,92a8929296968292,143032ccd4d4d4d4 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 5 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)