Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1943276B76054653B03A3C2D5A736236FE3D34289DA922A1173E98B4E5ED3F84EC0546B |
|
CONTENT
ssdeep
|
96:TnKOnNxlRSZSZS1yxLo40PRImpIIAF7DoU78T+lzBeyFuIcsPQPNTwUgeYusnXuw:TKPIIoLo40KmwzhM3V61nl |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fef8c1c5383ac2c4 |
|
VISUAL
aHash
|
ffffc0808030038f |
|
VISUAL
dHash
|
22002b3f37663e1e |
|
VISUAL
wHash
|
ffffd0808070039f |
|
VISUAL
colorHash
|
03e00000000 |
|
VISUAL
cropResistant
|
22002b3f37663e1e |
• Threat: Financial Investment Phishing
• Target: Financial services users
• Method: Credential harvesting via generic landing page
• Exfil: Obfuscated JS form submission
• Indicators: New domain, high-yield buzzwords
• Risk: High
Uses a professional-looking landing page to solicit user sign-ups for fraudulent investment services.
Uses unescape/obfuscated JS to hide exfiltration endpoints from basic security scanners.