Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T125032BB16442FC3B42DBD3DAA6B1476F32DAD306CD47231166FA870D4BD6DA2CE1A108 |
|
CONTENT
ssdeep
|
384:0MPzlfPYeBibXgNuvsPkPRiGaiKUhx9BJT7oIiWli3QV9wqFbj2j6jSMjajdEjKb:0MPzlf7nN1P0RiGaiKU3pT7HlifKQnL |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c3873c391cc5cecc |
|
VISUAL
aHash
|
0660747c2c6c6000 |
|
VISUAL
dHash
|
f4c8c4c8c9c9da24 |
|
VISUAL
wHash
|
7e7c7c7c6c6c6020 |
|
VISUAL
colorHash
|
38206008000 |
|
VISUAL
cropResistant
|
f4c8c4c8c9c9da24 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)