Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T138522035A000B93B81ABDAC5A279976F32C3836EDA031B0137F9C3989FD7D99DD15252 |
|
CONTENT
ssdeep
|
192:Xs98ydxjkZpID2VonzQSmyTxhE6GkliPAE8m0a3/7f3ntsUjYbOvxi:89rK7IDlnzDTxhE6DaP7f32b0U |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e93c9696c349363c |
|
VISUAL
aHash
|
3c8181f9fffffbff |
|
VISUAL
dHash
|
782723333b186362 |
|
VISUAL
wHash
|
0081819989eff9ff |
|
VISUAL
colorHash
|
060000001c0 |
|
VISUAL
cropResistant
|
782723f33a1a7368,00002432b2320c10,7f9f9f73f36fe77f,fb9f6969dee8bfff |
Fake Zoom login page with 1 form. Victim enters credentials which are captured and transmitted to attacker's server. Page may impersonate Zoom official login to appear legitimate.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.