Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16E9286F3978013BC0EC7DAE5B34AAB87A319C471F32A5158A0194C0C7AC93B6D5A7BD5 |
|
CONTENT
ssdeep
|
192:ihE5GL5tkbuCgL5aW6lqCrmo9PFzy4PFMoJs0+KNx5Lrrs8c81q2QfuQwTEDLp5k:PmtVCg9Kq6tz/PAIs8cWsfubTSfD6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cce63133333366c6 |
|
VISUAL
aHash
|
c0f8b81838181818 |
|
VISUAL
dHash
|
1430a0303030b0b0 |
|
VISUAL
wHash
|
e0f8f8f8f8f81818 |
|
VISUAL
colorHash
|
02000e00000 |
|
VISUAL
cropResistant
|
1430a0303030b0b0 |
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.