Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A6319031C0C58CEF0657C7D8CF36761EF3C6825DC6136A0195EA529E6A8AE66CD17884 |
|
CONTENT
ssdeep
|
24:tCcH4/uzxthDiG0lC9HXHJbqPHXHJaVh62pH1vb/2O92Aw6dT:lH6uzx2G0lIbMaVh6gTP/rdT |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc6666cce68c9933 |
|
VISUAL
aHash
|
1000181818181800 |
|
VISUAL
dHash
|
a020b2b2b2b2b2c4 |
|
VISUAL
wHash
|
3c143c3c3c3c1c7e |
|
VISUAL
colorHash
|
38200038200 |
|
VISUAL
cropResistant
|
8e33120f0b372b23,a020b2b2b2b2b2c4 |
• Threat: Brand impersonation and gambling promotion
• Target: Fans of Atletico de Madrid, particularly in Asia
• Method: Displaying the Atletico de Madrid logo to lure users to a gambling app.
• Exfil: Likely to drive users towards a gambling platform (K8)
• Indicators: Domain mismatch, presence of gambling branding alongside Atletico de Madrid logo, app download links.
• Risk: HIGH - Could lead to gambling addiction or financial losses.
Pages with identical visual appearance (based on perceptual hash)