Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16E8112F245118D3B1592879DDAF17A4CC172CA53CA0BBD20A1DD3BAB19D3D61CAAB231 |
|
CONTENT
ssdeep
|
48:jetcdr1BrsdAdEHjWyHjnjsjgKVhmIEcYcEVUL7rssFkB2lpKB3EWSQuw:qtiQOiDWyDjExVhpEjFmbHlAlEWSQ3 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
989f31717b58cc0e |
|
VISUAL
aHash
|
000f3f3c004a04ff |
|
VISUAL
dHash
|
325ff0f069d2dcd3 |
|
VISUAL
wHash
|
080f7f3c107e04ff |
|
VISUAL
colorHash
|
02000000007 |
|
VISUAL
cropResistant
|
377f339ccee0a2c4,3d96c3e3793c3e17,292b396563da9295,939313f7c6a9686a,a797abab99dc2209,ad637b239790ec4c,325ff0b069d2dcd1 |
Fake Jordanian Government Aid login page with 1 form. Victim enters credentials which are captured and transmitted to attacker's server. Page may impersonate Jordanian Government Aid official login to appear legitimate.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.