Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C2910E71A108B9771287D0E19B31D75FA3C6834DCEA74B0596F4839F5BCADA6CC17086 |
|
CONTENT
ssdeep
|
48:tPLBkU9eDxtloCtiAeKx/YaymBFGFB3B9N1Mm76uevdXSHN7+m7WKevdXSHNIm7X:t8DZWCG3jMm7NgdXZm7PgdXnm7ggdX4y |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a0d7d78a9a55668a |
|
VISUAL
aHash
|
ffc3c3c3ffc3c3c3 |
|
VISUAL
dHash
|
6896869eb3979697 |
|
VISUAL
wHash
|
fcc0c1c11b030303 |
|
VISUAL
colorHash
|
08000000e00 |
|
VISUAL
cropResistant
|
1c9cdcaa26aaaa55,6896869eb3979697 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 34 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)