Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A7D2867251002A3B02E7C3C9B391B71E92E3838DDB89081553FD876D5FEAF90D927666 |
|
CONTENT
ssdeep
|
768:GSXy5NXkKpPQh7U1okT/9jRCCoAFXQ7sOy2+y9BH4cLIe:3KpPQh7U1lQCouQ7sOy2+UBH4cLIe |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
876bfd32d12d9482 |
|
VISUAL
aHash
|
000000000000ffff |
|
VISUAL
dHash
|
1c49e3c3cc4cb600 |
|
VISUAL
wHash
|
80f571300406ffff |
|
VISUAL
colorHash
|
31000200038 |
|
VISUAL
cropResistant
|
008080084c808000,1409c3e3c3cccc36 |
• Threat: Credential/PII Harvesting
• Target: Users seeking trading automation
• Method: Brand impersonation of AI services
• Exfil: JavaScript-based form submission
• Indicators: Obfuscated script usage, generic marketing layout
• Risk: High (Data theft)
The site lures users into providing contact details to build a lead list for financial scams.
Uses the reputation of 'Mistral' to build fake trust in a non-existent trading platform.
Pages with identical visual appearance (based on perceptual hash)