Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10C627436A4803037521B0EE5B56273ABB2F7C40BD66F181065FC878C1BDAD99DB27993 |
|
CONTENT
ssdeep
|
384:ryUvUJRsi8vn7m0Pkcw/a5IvyFvuBGY1V8T6MX:8JRsion7mGkcAa5Iq1uBGY1V8WMX |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ceb2b3c6ed0b2419 |
|
VISUAL
aHash
|
ffff001010303800 |
|
VISUAL
dHash
|
080c446261647060 |
|
VISUAL
wHash
|
ffff003838383c38 |
|
VISUAL
colorHash
|
1a0000001c0 |
|
VISUAL
cropResistant
|
0c08144c4c4c0008,165c392399d95a5a,e3e3d7d2d38d2272,524ab1b3ba929292,2626674999d92a2a,6b8bcbabaa525351,1c62626264607062 |
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.