Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14F51766411264A6E50939760F7B1BF16E1B8D3C4E356851C71FC90223ACAC64CCDD2A0 |
|
CONTENT
ssdeep
|
48:TRhwtWA/MGrOKADFkDmCQ4g1pOerFc0q7ve+7iK:TRbWOfJ+U1vrFc0q7vxiK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc993366cc996633 |
|
VISUAL
aHash
|
0000181818000000 |
|
VISUAL
dHash
|
3004b2b2b2301000 |
|
VISUAL
wHash
|
03031b1bd8d8e0f8 |
|
VISUAL
colorHash
|
38006000080 |
|
VISUAL
cropResistant
|
86c094338486c7b3,3004b2b2b2301000 |
⢠Threat: Phishing Gate/Bot Filter
⢠Target: General users
⢠Method: Slide-to-verify captcha to hide malicious content
⢠Exfil: Obfuscated script payloads
⢠Indicators: Obfuscated JS code, suspicious TLD
⢠Risk: High
The site acts as a filter to ensure visitors are human before exposing them to the final phishing payload, preventing automated analysis.
JavaScript code is heavily encoded to hide malicious URLs and exfiltration logic.