Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1902285B25144602F622B96CB9F266B6C32B721BFE5B70141B7FC47C4CB9AC91EC0A844 |
|
CONTENT
ssdeep
|
192:WdatU40fAAqRZ69B+5HlOCLGoQ407AAqRZ6uGmwQ9vc:T0yRZ69WHl0s0ORZ6owQpc |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92926c6d6d929ee4 |
|
VISUAL
aHash
|
7e2c2c6c00180000 |
|
VISUAL
dHash
|
f4c9c9c9d230b270 |
|
VISUAL
wHash
|
ff7e7c6c003c1838 |
|
VISUAL
colorHash
|
310001c0000 |
|
VISUAL
cropResistant
|
8e1e3c78e1c3878e,f4c9c9c9d230b270 |
• Threat: Credential harvesting phishing kit
• Target: Polly Penguin users internationally
• Method: Fake airdrop page stealing user data
• Exfil: Data sent to unknown server
• Indicators: Domain mismatch, free hosting, obfuscated JavaScript
• Risk: HIGH - Immediate credential theft
Pages with identical visual appearance (based on perceptual hash)