Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1902285B25144602F622B96CB9F266B6C32B721BFE5B70141B7FC47C4CB9AC91EC0A844 |
|
CONTENT
ssdeep
|
192:WdatU40fAAqRZ69B+5HlOCLGoQ407AAqRZ6uGmwQ9vc:T0yRZ69WHl0s0ORZ6owQpc |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92926c6d6d929ee4 |
|
VISUAL
aHash
|
7e2c2c6c00180000 |
|
VISUAL
dHash
|
f4c9c9c9d230b270 |
|
VISUAL
wHash
|
ff7e7c6c003c1838 |
|
VISUAL
colorHash
|
310001c0000 |
|
VISUAL
cropResistant
|
8e1e3c78e1c3878e,f4c9c9c9d230b270 |
• Amenaza: Kit de phishing para robo de credenciales
• Objetivo: Usuarios de Polly Penguin internacionalmente
• Método: Página falsa de airdrop que roba datos de usuario
• Exfil: Datos enviados a servidor desconocido
• Indicadores: Dominio no coincide, hosting gratuito, JavaScript ofuscado
• Riesgo: ALTO - Robo inmediato de credenciales
Pages with identical visual appearance (based on perceptual hash)