Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15EA1673360006D3741D3C7DA9756F21EA6C3A209CE930A05FAF9476E5EF5EE0ED11169 |
|
CONTENT
ssdeep
|
48:ze70LUx8K7GjpKf5dQVeaz2LUKEzTNmTNMcy4zcAuRlqRAbTBKDcyJaz12D1n4HD:zPwUkwyLunl3uaxE1guPde/wRK5 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c6c6383d973c3293 |
|
VISUAL
aHash
|
00307c7c7c001034 |
|
VISUAL
dHash
|
c4e1e9e0c863f0d4 |
|
VISUAL
wHash
|
06747c7c7e203c7c |
|
VISUAL
colorHash
|
30001000088 |
|
VISUAL
cropResistant
|
ebccd5e3cb996667,bc3c7c7cb69a9bd7,0000000948000000,c4e1e9e0c863f0d4 |
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.