Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T124F12033D22069370793C5D1BA6166BF63E04386DA0B1A4167FE934D0FE5D87EE7A206 |
|
CONTENT
ssdeep
|
192:w0SbrXtYoTxsoonoruk55RpLKF9whund9Sba:jCXtdso5ruk55RpuF9Pd9ua |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92a2ede9929292ed |
|
VISUAL
aHash
|
ff002e0e00000400 |
|
VISUAL
dHash
|
3bc7ccccc3dcf84c |
|
VISUAL
wHash
|
ff013f2e20007cfe |
|
VISUAL
colorHash
|
000000001c0 |
|
VISUAL
cropResistant
|
00032b23232b022b,aa829a1a7a9282a2,cfc7ccecc3ddf86c |
• Threat: Investment Fraud
• Target: Financial/Investment
• Method: Impersonation/Deception
• Exfil: Unknown (JS obfuscation)
• Indicators: Obfuscated source code, new domain
• Risk: High
Uses professional design to lure users into depositing funds into a non-existent or fraudulent investment account.
Hides malicious exfiltration scripts from static analysis tools.