Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18DA265E2D2056A7F032BD2D5D776BF2E73C2438AEE82050592FD83645769E91EC134AC |
|
CONTENT
ssdeep
|
384:d59Y+0P58CDi3dsyvpAfvknELcdrlNLeSrfoMGbdHXox0PV:n9chqDLfnKPV |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
996c663366cc9966 |
|
VISUAL
aHash
|
0018181818181800 |
|
VISUAL
dHash
|
c432b2b2b0f0f0cc |
|
VISUAL
wHash
|
003c3c3c3c3e7e3e |
|
VISUAL
colorHash
|
300000001c0 |
|
VISUAL
cropResistant
|
afaf4f45474fadaf,c432b2b2b0f0f0cc |
Fake Safirbet login page with 2 forms. Victim enters credentials which are captured and transmitted to attacker's server. Page may impersonate Safirbet official login to appear legitimate.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.