Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15E139571E0147D3B019392E5E7326BAFA3C48245CA130755A3FC9B6DAFD7E94DC2A248 |
|
CONTENT
ssdeep
|
384:tUB44MlezI4OE52xLKIhQtaSc4aaTLSf0rQyjFuBIcesHfft:eB44RzIPlxLKI2gSc45TLScrpjFnkF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec3e93cb962861b1 |
|
VISUAL
aHash
|
9f9f8191d1f1f9fe |
|
VISUAL
dHash
|
2b36333737030304 |
|
VISUAL
wHash
|
17138191f0f0f8fe |
|
VISUAL
colorHash
|
07000000c41 |
|
VISUAL
cropResistant
|
2b36333737030304 |
β’ Threat: Financial Investment Fraud
β’ Target: Retail Investors
β’ Method: Credential Harvesting via Trading Portal
β’ Exfil: Obfuscated JS/Remote Hook
β’ Indicators: Obfuscated source code, low domain age
β’ Risk: High
The site mimics a legitimate trading platform to deceive users into entering their credentials, which are captured via obfuscated JS.
Platform uses fake 'Copy Trading' promises to lure users into depositing funds into non-existent accounts.