Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D9E2337CDD922A3A043303C17BAAA3AE57985341E2534A8643FE479E85C9DC3F97E744 |
|
CONTENT
ssdeep
|
384:E8VKeSVoFfXTV11obgNgWdsyEOBemdpM2lAna9tRj6VlpgjGiy+Ii7na3cYeC7Bf:EMSVoFfXTVrNE6emdGctl6VSIl99W9A |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ee669151ef1111ea |
|
VISUAL
aHash
|
00f3f3f3f100ffff |
|
VISUAL
dHash
|
92272f6f6398c128 |
|
VISUAL
wHash
|
00f181e3b100ffff |
|
VISUAL
colorHash
|
07001000007 |
|
VISUAL
cropResistant
|
e7272f2b2f6763e3,00000048402d2d60,8094000092928000,7a5aca626eded424,8182a644242e5e3c,cdcdc5a8c8cccdce |
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.