Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C522863310D05A3F416743DD76B16BAE7283835CD9D72611D6A9C77B9AC2EB0FC09826 |
|
CONTENT
ssdeep
|
96:Ka8E7IkSZSZSTUeacHwX/bH54ZuZgCOZmDZ+6KLwQ1Pc/gfPJd7PC2MPV2lhxVmx:zDuII47t6mF+Kk62AUkf+CeC |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc1963c3cfc2c938 |
|
VISUAL
aHash
|
f98f87939fff87ff |
|
VISUAL
dHash
|
633e3f3727172c2e |
|
VISUAL
wHash
|
9903038397ff87c3 |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
633e3f3727172c2e |
Fake Polymarket page designed to appear in search results and trick users into visiting. May redirect to credential harvesting pages, malware downloads, or serve as a trust-building step before requesting sensitive information.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.