Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18B3153C191B2A63762929389B7CB9B7972C70505DA170A1127EF83A909F1D93F837486 |
|
CONTENT
ssdeep
|
48:SoUcs52p3qPdzoQXqS6v7r7p9P49jG1pc:G278qDvz49K1pc |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8da5278d8d27a58d |
|
VISUAL
aHash
|
6200001818180000 |
|
VISUAL
dHash
|
96210032b2320c10 |
|
VISUAL
wHash
|
63010c3c3f3f0f0f |
|
VISUAL
colorHash
|
380000001c0 |
|
VISUAL
cropResistant
|
000020e4c4020000,96210032b2320c10 |
Fake CardStarter site positioned to capture victims through SEO tactics, typosquatting, or paid advertising. Serves as entry point for multi-stage attacks including credential theft and malware distribution.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.