Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12D81BF70304C9D3F45C287D5AB24672EA65782E1D6470A4872D4D75B8EFFF82CC10BA9 |
|
CONTENT
ssdeep
|
96:/JovWoqMZOvWodvTXey8ul2lq21crATcCzW:/JovWSZOvWqvrYucLak4CzW |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f3d94be24848e64b |
|
VISUAL
aHash
|
ffffffffffff0000 |
|
VISUAL
dHash
|
2b580a32080cb085 |
|
VISUAL
wHash
|
00efefff3c240000 |
|
VISUAL
colorHash
|
0e000038400 |
|
VISUAL
cropResistant
|
2b1a4a183a324d4c,208085a0d5a59000 |
Victim enters credit/debit card details including CVV and expiration. Card data is captured and can be used for fraudulent transactions or sold on dark web markets.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)