Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F241ED90724541FB051262C5BB16AF6AF3C55A88C6710A0597FF638E6F88C4BAC2B70D |
|
CONTENT
ssdeep
|
48:UV8VckcSaz3omEXr6BF8Gc7vkrwv+ZU0zMOHgnXTBS:UV8Wku0XrSF8Gc7vkrwv+ZU0zxAnXU |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ab1c7438771cf618 |
|
VISUAL
aHash
|
003f3f2feded09e0 |
|
VISUAL
dHash
|
b3fb695bcb0b6b4b |
|
VISUAL
wHash
|
003f3f2fede901e0 |
|
VISUAL
colorHash
|
30000038000 |
|
VISUAL
cropResistant
|
b3fb695bcb0b6b4b |
Fake Netflix login page with 2 forms. Victim enters credentials which are captured and transmitted to attacker's server. Page may impersonate Netflix official login to appear legitimate.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.