Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17A42537030147A7A16D386F2B211AB7AF1EDC78DCD1B8656B6F8C36A2BC5C94CE02751 |
|
CONTENT
ssdeep
|
192:jn98w0ZtqMz0OkbkL5eopbXHHI5dmALqASHCBHNOggFxV:j9utt0OkbCTHoDTSHsHNU |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
999267656436b699 |
|
VISUAL
aHash
|
423c3c3c18001800 |
|
VISUAL
dHash
|
d4f0e8e0b2f07072 |
|
VISUAL
wHash
|
7e7e7e3e3c003818 |
|
VISUAL
colorHash
|
38000c00008 |
|
VISUAL
cropResistant
|
a292802b3b8080a2,d4f0e8e0b2f07072 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)