Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16194D9B2F2F017BB001E83D5F2779921EBD530E9E6818FC4829C4BE9A546C6D7CD158A |
|
CONTENT
ssdeep
|
1536:injzk6IB2oTfi8J9CFNull0IByfi82CSvaYBJSuYDbSNJ/AZe80jNBv8M+QHk+wk:z2mFED+TsHJm3UW/feVuhE/Hx4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9f5015aee0aee2e4 |
|
VISUAL
aHash
|
ff009cfdd9bdbfff |
|
VISUAL
dHash
|
58d8316b2b696d69 |
|
VISUAL
wHash
|
ff0000b98185bfbf |
|
VISUAL
colorHash
|
06400040003 |
|
VISUAL
cropResistant
|
58d8316b2b696d69,f979a991919b8bcb,0040406969602080,863e7278e2c38124,0b1f37270f0cce46 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 12 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)