Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1464153771B02942E4764C1D85EC7F4298F9A8AD3E9316600DDCA8F8D0CE2AB0D0B7126 |
|
CONTENT
ssdeep
|
48:SYMBnNaRbU7bUFrHdI2FsUPsbDC3IlUUWtKQhdLpWcmUA7:aBnNx+I/Chpptm |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cccc9933333366cc |
|
VISUAL
aHash
|
1838381800000000 |
|
VISUAL
dHash
|
1432b2300c100030 |
|
VISUAL
wHash
|
3c3c3c3c031f0f1f |
|
VISUAL
colorHash
|
38000600030 |
|
VISUAL
cropResistant
|
1432b2300c100030 |
Fake Galabet site positioned to capture victims through SEO tactics, typosquatting, or paid advertising. Serves as entry point for multi-stage attacks including credential theft and malware distribution.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.