Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C14176228087A36B1F0120DEB9E5129CD2474E5BA973790595E5CB2EFBCAD8FC1D5308 |
|
CONTENT
ssdeep
|
48:mtdAZXLwZdDihYDdpCZcx65kcXvu2WoZm7OQvAU:htMZJiGDzCZcx65rXvd3m7bIU |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
db8c24c33339cb93 |
|
VISUAL
aHash
|
c0d8b8987c7c3800 |
|
VISUAL
dHash
|
1030303048484802 |
|
VISUAL
wHash
|
e0f8f8f8fc7c3800 |
|
VISUAL
colorHash
|
000000001c0 |
|
VISUAL
cropResistant
|
1030303048484802 |
• Amenaza: Phishing
• Objetivo: KOSGEB
• Método: Suplantación de identidad de portal gubernamental
• Exfil: Credenciales vía redirección e-Devlet
• Indicadores: Dominio .com recién registrado
• Riesgo: Alto
The site mimics a government application portal to harvest e-Devlet credentials.
Uses KOSGEB official branding to build false trust.