Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E85131F15245593500A3C2EAFBF87B1B83994B88CDA34887A3C8C3990BC6D61ECD4290 |
|
CONTENT
ssdeep
|
48:KkBnqJOdhOqIvqvwzi4fs5aDmgCJ7wCfpw684+hwstCkBZ:KkY0voqvwzi6s5dl7Zpw5twmCa |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc993366cc9933cc |
|
VISUAL
aHash
|
0000181818000000 |
|
VISUAL
dHash
|
100832b2b24c3000 |
|
VISUAL
wHash
|
ff00383c3c3c0081 |
|
VISUAL
colorHash
|
38000030000 |
|
VISUAL
cropResistant
|
a2a1c1a58dc0a0a0,100832b2b24c3000 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)