Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12251C0B282C8E47B46428AD0EB32AF1FF743D1C5DA864D46C5F9475D1A89F16CD330A5 |
|
CONTENT
ssdeep
|
24:haaJrUeCMCut5hHuCX933TusScQbnORBRh5fmclFiqmcDLhmccKmcku3mBGl6ISO:meHuCN3juRgB/cyFe6ghZmWBGRrEMn |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8c9c773131337399 |
|
VISUAL
aHash
|
18181c1818001800 |
|
VISUAL
dHash
|
f2f2f2f2b2e2b2b2 |
|
VISUAL
wHash
|
1f3f3f1f1f181810 |
|
VISUAL
colorHash
|
38000030000 |
|
VISUAL
cropResistant
|
a280b29696c280a2,f2f2f2f2b2e2b2b2 |
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)