Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C6213016D7899C0CF1B7E0C8ADF0CB4E27618A46C306076892D073B9A18D5B198B6099 |
|
CONTENT
ssdeep
|
24:n/YrdIvv3AnsYPRNM0d9D55NyYyvD7wYKZwou+FgkNS:nSav6v55Nf8Is7+xS |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e666999933668ccc |
|
VISUAL
aHash
|
e7e7ffa5e7ffffff |
|
VISUAL
dHash
|
0828224c4c300000 |
|
VISUAL
wHash
|
e4f4f8e0243c3030 |
• Threat: Phishing attempt targeting K8凯发 users.
• Target: Users of K8凯发 platform.
• Method: Displaying a fake security check and prompting users to enter the K8凯发 platform through a malicious link.
• Exfil: Unknown, likely redirects to a malicious site or harvests credentials on the next page.
• Indicators: Suspicious domain name, brand impersonation, Chinese language content.
• Risk: HIGH - Likely redirects to a malicious page aimed at stealing credentials or sensitive information from K8凯发 users.
Pages with identical visual appearance (based on perceptual hash)