Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T122D1FE256161ACB3602BE7DA426CE30F72C7C16DD9738B01A7F6A7CC5BDED9A9C05102 |
|
CONTENT
ssdeep
|
96:tDHqoI6oaihEDLrKENgZUil76QZ2oDJyAqLW+Etf3yBrGcR:NKox3ihuBNgR76toDJELZEt6BycR |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec4d9392676d1a92 |
|
VISUAL
aHash
|
7ffb8bd1ff9fd3ff |
|
VISUAL
dHash
|
c03636a7642a2228 |
|
VISUAL
wHash
|
7e7b0b117a1e024e |
|
VISUAL
colorHash
|
070010001c0 |
|
VISUAL
cropResistant
|
c03636a7642a2228 |
Fake Telegram page designed to appear in search results and trick users into visiting. May redirect to credential harvesting pages, malware downloads, or serve as a trust-building step before requesting sensitive information.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)