Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CE32A4B82061F93B14A3D2D1A7B9232FB3D0C2AAD4234B81D7F9876C4FD9D479C56242 |
|
CONTENT
ssdeep
|
192:H1r/YWDreCsglpy+/zbXjWKkzyyotG6AUUWW:Vr7+Cx/zTydzyyotG6AwW |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b83cc7c39d26ce18 |
|
VISUAL
aHash
|
ffc383838fffe7ff |
|
VISUAL
dHash
|
63173f1e1a8c0e33 |
|
VISUAL
wHash
|
bb01010383ffe7ab |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
63173f1e1a8c0e33,8acaaecacaced0c8,fccacecacaccc8ee |
Fake Telegram site positioned to capture victims through SEO tactics, typosquatting, or paid advertising. Serves as entry point for multi-stage attacks including credential theft and malware distribution.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)