Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A2E0C0E07D652198420279C21AD3AB0C27375771D76B4888A1A16432A1CE3DCD465BD5 |
|
CONTENT
ssdeep
|
6:qzxG6cqlfuq+StbVfF8sRnuHkQRdFh4o/2eQ8a0iYDoyW/uMg66i5+30B9BF+Xz:kxpcAuq+ixt3IZdFhzQY4l8jiCUjF+j |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9e8673d961669869 |
|
VISUAL
aHash
|
1c3e3e36183c0000 |
|
VISUAL
dHash
|
e0e4e4e4b2f0ccf0 |
|
VISUAL
wHash
|
7e7e7e7e3c3c0000 |
|
VISUAL
colorHash
|
30206008000 |
|
VISUAL
cropResistant
|
e0e4e4e4b2f0ccf0 |
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)