Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T141330021D384235DE8A954A2E270AF9C83E5445E83310A58AD1AE7BF1CCE061F9777FD |
|
CONTENT
ssdeep
|
384:jo1ZDp9yFyMC9X+iCdO99OpsTZ+UDPk3QQvrxti9FG0LndswIs13sxuWCBeaQDyX:gZDpkc+eUsdswIs13sdWu33Rq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc6666ccc6999933 |
|
VISUAL
aHash
|
1800181818181800 |
|
VISUAL
dHash
|
6060b2b2b2b2b2c4 |
|
VISUAL
wHash
|
3c3c38383c3c187e |
|
VISUAL
colorHash
|
30200030200 |
|
VISUAL
cropResistant
|
8e33120f0b372b2b,6060b2b2b2b2b2c4 |
• Threat: Brand impersonation phishing targeting users seeking Atletico Madrid related content.
• Target: Users searching for Atletico Madrid content, particularly in regions where K8.com is accessible.
• Method: The site falsely claims a partnership with Atletico Madrid to entice users to download apps or visit other linked sites.
• Exfil: Unknown, likely redirection or data harvesting through app download.
• Indicators: Domain name mismatch, recent domain registration, brand impersonation of Atletico Madrid, and promotion of app downloads.
• Risk: MEDIUM - Misleading content and potential for redirection to malicious or undesired apps/sites.