Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10233A43B2CB0D23700634DE1E6A12F56A6A8ED84D6F2B185DDFDC3954FF2EA4C416881 |
|
CONTENT
ssdeep
|
1536:vJUU/SdV7r2QjzhAHbwHl4FhfvYvEnmN7Cbju:v6aOl46Niju |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
87947c305e38c7ce |
|
VISUAL
aHash
|
06277f3f3f660070 |
|
VISUAL
dHash
|
d4cac0cac8c81ec4 |
|
VISUAL
wHash
|
06077f7f7f620070 |
|
VISUAL
colorHash
|
380020001c0 |
|
VISUAL
cropResistant
|
d4cac0cac8c81ec4 |
Fake Polymarket site positioned to capture victims through SEO tactics, typosquatting, or paid advertising. Serves as entry point for multi-stage attacks including credential theft and malware distribution.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.