Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T156F22420741926B3037385C5F5323F86B6A3F74FD19A48916ABC518C0FE7CB1BA295B6 |
|
CONTENT
ssdeep
|
768:VfO15SgFYN2pf5sNFGsPRI5dQ4sd8TASLdibdR4MdL4+dzgEDDYZ5nBS8s8wYhm2:FO15SgFYN2pf5sNFGsPRI5dQ4sdMASLB |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8e0fc3e170bab878 |
|
VISUAL
aHash
|
ff00000000ffffff |
|
VISUAL
dHash
|
c1e0f83d0e2b2b29 |
|
VISUAL
wHash
|
ff00000000ffffff |
|
VISUAL
colorHash
|
06007000000 |
|
VISUAL
cropResistant
|
01c1e0e070f8fe7d,29002b2b2b291400,e0e070f8ff3d0e1f |
• Threat: Financial Investment Phishing/Fraud
• Target: Retail investors
• Method: Impersonation of an investment firm to harvest user credentials/financial info
• Exfil: JS-based form submission
• Indicators: Extremely young domain, suspicious obfuscation in source
• Risk: High due to potential for capital theft
The site lures users into 'investing' funds into a fake brokerage platform. JavaScript obfuscation is used to hide the data submission process.
The 'Open Account' link likely leads to a registration form designed to steal PII and financial login details.
Pages with identical visual appearance (based on perceptual hash)