Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15BE2782191182D3E92170BD9D327F339302F9389DB8E1128AD7912B15BDADE9B43B5C8 |
|
CONTENT
ssdeep
|
384:YcLq8seONY58r/m1GcuFiNBEqlCXA91TlHvs2YsQb1L+Db/j:YcJ958r/m1GcuFiNBEqlCXqMXAb |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b44bb54aa55aec92 |
|
VISUAL
aHash
|
8c08000010f00f1f |
|
VISUAL
dHash
|
5598b979b5a3bc7e |
|
VISUAL
wHash
|
ffcf000011f11f3f |
|
VISUAL
colorHash
|
30c00018000 |
|
VISUAL
cropResistant
|
62240ae636a4b43a,5598b979b5a3bc7e |
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.