Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15072A771A145943B11D3D6C49A30B72AB3F6C2C6E6431342D6F9837EEADEDA0EC12469 |
|
CONTENT
ssdeep
|
384:XfV0PFvULTu/TgPTnQT9GTMTJ+eVTYknOUUNNB2a7+olDM0fDuefqQ0:PV0PFvULTu/TgPTnQT9GTMTJ+ehYyOUv |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a6af19407ffc4143 |
|
VISUAL
aHash
|
91b7f7ff73511100 |
|
VISUAL
dHash
|
2767e727c7c7a75a |
|
VISUAL
wHash
|
81b7f7fff3111000 |
|
VISUAL
colorHash
|
0a080010041 |
|
VISUAL
cropResistant
|
a082d26a72ba582c,a0c068303418db8c,c8ccc6e6f5656e2c,279cf8e186318286,f8c000b8418d3135,3598c0c6ca9c2c1c,8041404040404082,0000008000808000,0402020000000000,2767e727c7c7a75a |
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.