Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D542B932A0002A3F531392F6631F239ED341DAC9D2C61E8A52FDC75D27C2E95EE17569 |
|
CONTENT
ssdeep
|
384:8mxJsL6t0KgPOVjyxKmdIkUqt70kIICrJ3bWHjcu/Grs+t7f0zbry:xJsL6t0KgPOVjyxKmdIkUqt7zII7U3 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b14eb9c958e18eb8 |
|
VISUAL
aHash
|
ff00000000ffefcf |
|
VISUAL
dHash
|
fbe4e5d5f41a1a1b |
|
VISUAL
wHash
|
ff30002000ffefcf |
|
VISUAL
colorHash
|
07c00000000 |
|
VISUAL
cropResistant
|
040b0b2323cb00fc,dbdbb632e337356d,baa96ccde969696b,609c9b1e1c1b1a1b,9fbbbab6b4f274f0,fce4e4e5e5d4b432,32323153561cb8f9 |
• Threat: Financial Investment Scam
• Target: Retail Investors
• Method: Impersonation of an AI investment service
• Exfil: JavaScript-based submission
• Indicators: Extremely recent domain, code obfuscation
• Risk: High
Site attempts to lure users into signing up for a fake financial service to capture PII or login credentials.
JavaScript used to dynamically inject or process form data to obfuscate where the user data is sent.