Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11022A63660D0252F017753D9BBA177ABA192824CE9D62601EAFDC32B4DD7DA0F807896 |
|
CONTENT
ssdeep
|
192:v4hJVII4L2AlBclM2R3tc8bx2h64WJkf1HWBrgReffaC:v4hXII4LL8M2JtcEx257JSgReff9 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc29c3c3cf4ac13c |
|
VISUAL
aHash
|
f98f83939fff87ff |
|
VISUAL
dHash
|
6b363737270b2c2c |
|
VISUAL
wHash
|
8903038393ff87cf |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
6b363737270b2c2c |
Fake Polymarket site positioned to capture victims through SEO tactics, typosquatting, or paid advertising. Serves as entry point for multi-stage attacks including credential theft and malware distribution.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.