Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C4B3033083911A22C99393C4FBF5578B5170934AC7670D88B3F45726BFCBCA8EE16996 |
|
CONTENT
ssdeep
|
1536:io4R4xx/qP1qEILqeee2eeeDeeeyeeeEeee7eeeDeeeXeees1GkekTS011Nw0Zcu:in4xAcWGkeke011Zv |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93a738b4606ff152 |
|
VISUAL
aHash
|
030f6f677eff0008 |
|
VISUAL
dHash
|
8339d9cacc9c7999 |
|
VISUAL
wHash
|
010f6f6feeff0008 |
|
VISUAL
colorHash
|
13c00008000 |
|
VISUAL
cropResistant
|
8339d9cacc9c7999 |
• Threat: Financial Investment Fraud/Phishing
• Target: Investors
• Method: Malicious script injection
• Exfil: Form data and credential harvesting
• Indicators: Obfuscated JS, multiple login/signup forms
• Risk: High
The site uses malicious scripts to intercept login credentials entered into the provided forms.
Form inputs are captured and transmitted to external servers via hidden JS logic.