Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T129A2D7A5D288B61F64E182BDEA60BF0AA957E244C313BB05F9F4B5D817CD4CEE45720C |
|
CONTENT
ssdeep
|
384:Hq9rXkLaRPe9uFafUTqeVL+TFfKh+uqaBYeCHFLnfKkEV9:K9rXkmF1TNVmKh7YLCV9 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b1668c999993b333 |
|
VISUAL
aHash
|
c3c3c3c3c3c3c3c3 |
|
VISUAL
dHash
|
16160e0e0e1e0616 |
|
VISUAL
wHash
|
c3c3c3c3c3c3c3c3 |
|
VISUAL
colorHash
|
07600030000 |
|
VISUAL
cropResistant
|
16160e0e0e1e0616 |
• Threat: Browser-locking scareware
• Target: Facebook users
• Method: Malicious JS execution for pop-up loops
• Exfil: User interaction logs/Click tracking
• Indicators: Obfuscated JS code, scare text
• Risk: High
Uses obfuscated JS to trigger infinite alert pop-ups or window resizing to trap the user.
Uses fake security warnings to manipulate the user into clicking a malicious link.