Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13C1253B022A1ED36959BC3F74060A31FB1C6DB45AC67A3044BE2472FDBCCE66CC42159 |
|
CONTENT
ssdeep
|
192:4V0NuMYQ+cdAH2czrJ5gaH9/cCP32Gb3G7ZGHlapA3nfCVohia:9X+cdAH2czrJ5gMBFP32Gb3G7ZGHopA7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc1c4bc3c34c9e2e |
|
VISUAL
aHash
|
bb87939be7e781c3 |
|
VISUAL
dHash
|
231f37230c0d2333 |
|
VISUAL
wHash
|
b3878393e7e78181 |
|
VISUAL
colorHash
|
070020001c0 |
|
VISUAL
cropResistant
|
231f37230c0d2333 |
Fake Telegram site positioned to capture victims through SEO tactics, typosquatting, or paid advertising. Serves as entry point for multi-stage attacks including credential theft and malware distribution.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.