Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14E32B437328426BFC6C343B4B3267BFE73929585C5178399D6F8821D63D8C968C316A9 |
|
CONTENT
ssdeep
|
192:6SLKro6DcZUhjLawl8iIAp2kHJUc7rxUPL5LPLEL4mLQLdLdLQ/LOkp2DgMpYxnK:luPCUhSOxIAgkHJUc7rqPL5LPLEL4mL0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9393646d3c666c99 |
|
VISUAL
aHash
|
002c0c0c1c002000 |
|
VISUAL
dHash
|
60d8d9195969c4c4 |
|
VISUAL
wHash
|
7f7c3c1c1c3c7070 |
|
VISUAL
colorHash
|
30401010000 |
|
VISUAL
cropResistant
|
c477c6861cb9a3b2,60d8d9195969c4c4 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)