Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C351ED40724582FB025212C5BB1BAF6AF3C54B84C5B61A0953FB538E2FCDC5BAC6B209 |
|
CONTENT
ssdeep
|
48:UV8Igc2cREvjr6bP8yBkBbBIBk9IBhBOBMBU0zMOHgnXTBncv:UV8I2jvjrs82klYk9YnCsU0zxAnXBk |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c927d827c83fc827 |
|
VISUAL
aHash
|
01010000e0e080f8 |
|
VISUAL
dHash
|
33e36a5acb8b2393 |
|
VISUAL
wHash
|
011b3b2be9e981fc |
|
VISUAL
colorHash
|
38c00000000 |
|
VISUAL
cropResistant
|
48f2d0f2f2f6eccd,fefefefafab2baaa,33e36a5acb8b2393 |
Fake Netflix login page with 2 forms. Victim enters credentials which are captured and transmitted to attacker's server. Page may impersonate Netflix official login to appear legitimate.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.