Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C14176228087A36B1F0120DEB9E5129CD2474E5BA973790595E5CB2EFBCAD8FC1D5308 |
|
CONTENT
ssdeep
|
48:mtdAZXLwZdDihYDdpCZcx65kcXvu2WoZm7OQvAU:htMZJiGDzCZcx65rXvd3m7bIU |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
db8c24c33339cb93 |
|
VISUAL
aHash
|
c0d8b8987c7c3800 |
|
VISUAL
dHash
|
1030303048484802 |
|
VISUAL
wHash
|
e0f8f8f8fc7c3800 |
|
VISUAL
colorHash
|
000000001c0 |
|
VISUAL
cropResistant
|
1030303048484802 |
• Threat: Phishing
• Target: KOSGEB
• Method: Impersonation of government portal
• Exfil: Credentials via e-Devlet redirection
• Indicators: Newly registered domain .com
• Risk: High
The site mimics a government application portal to harvest e-Devlet credentials.
Uses KOSGEB official branding to build false trust.