Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T179F319FB7186331607B3A0B5102F310AF237958E5C8D5059F21CA5A5BF68A8F4267E7E |
|
CONTENT
ssdeep
|
3072:US5fP7V7ITSbQ84bGemHNwcv9VBQpLl88SMBQ47GKF:US17KTSbQSemHWK9VC78UBQ47GKF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f2d9a9668b592619 |
|
VISUAL
aHash
|
fcfcc8fcf4e0c0e0 |
|
VISUAL
dHash
|
001010186c0c1004 |
|
VISUAL
wHash
|
fcf8c8ecfce0c0c0 |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
001010186c0c1004 |
• Threat: Credential harvesting phishing targeting Turkish citizens.
• Target: Users of the Turkish e-Government Gateway (e-Devlet Kapısı).
• Method: Fake login form designed to steal T.C. Kimlik No (Turkish National ID) and e-Devlet password.
• Exfil: Likely exfiltrating data to an attacker-controlled server.
• Indicators: Domain mismatch (basvuruolustur.com vs turkiye.gov.tr), recently registered domain, brand impersonation.
• Risk: HIGH - Immediate risk of identity theft and access to sensitive government services.
Pages with identical visual appearance (based on perceptual hash)