Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17C1273312190753742A396D9FB25935FB7A2C296EA170F11A2F8C34DDFE7C4ADC1214A |
|
CONTENT
ssdeep
|
192:CNhb2e44CRsKaI4dHshrd4/p1LxA0FOui8c9HocaFQ5d2fKDmktvJ:0xT44ChaI4dHMrd4blFiboA2fUvJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93621cec5d6db924 |
|
VISUAL
aHash
|
00242424e7ff040e |
|
VISUAL
dHash
|
24cdc9c9ce3bc4dc |
|
VISUAL
wHash
|
0074056cffff260e |
|
VISUAL
colorHash
|
30003000180 |
|
VISUAL
cropResistant
|
24cdc9c9ce3bc4dc |
• Threat: Financial Investment Fraud
• Target: Investors seeking AI opportunities
• Method: Impersonation of a regulated financial firm
• Exfil: JavaScript-based form submission
• Indicators: Extremely young domain, suspicious return claims, obfuscated scripts
• Risk: High (Loss of personal data and capital)
The site lures victims with high-yield investment opportunities. Once contact is established, attackers solicit funds under the guise of trading.
Captures user contact information for follow-up social engineering or identity theft.
Pages with identical visual appearance (based on perceptual hash)