Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BBE28230A000597F48CBA2DA6B318F8FA3E6E348CE131A5652FD97990FCBD14DD5BA54 |
|
CONTENT
ssdeep
|
384:TrqqmH8ig5MSWuFM8p0v03JO4rrE1IbO0WvFYAknmGzBycyQfR9s5:/qqm5gWBx8C2EWrEIK/kycyQTs5 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b021c537b64a4fe9 |
|
VISUAL
aHash
|
000600040600ffff |
|
VISUAL
dHash
|
7e9e93bd9c7ea100 |
|
VISUAL
wHash
|
020f49050f06ffff |
|
VISUAL
colorHash
|
120030000c0 |
|
VISUAL
cropResistant
|
5efedcfcedcd8f0f,1e0bcbe7c7cfd3f3,a2a040232b8080a2,0000000001020202,6ade9b93bd9d7ea2 |
• Threat: Financial Phishing/Credential Harvesting
• Target: Banking customers
• Method: Impersonation of a legitimate financial institution
• Exfil: JavaScript-based obfuscated data exfiltration
• Indicators: Obfuscated JS code, fresh domain, no corporate footprint
• Risk: High
The site lures users to register/login to harvest banking credentials and sensitive PII.
Use of base64 encoding to mask the destination and nature of input data submission to avoid static analysis.