Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T113A3DD238159752A4437C3C0347A5B3BE5A69D8FFEE709004EDC87FA2AF9CA0741A65D |
|
CONTENT
ssdeep
|
1536:YgytvtpR4nXBKpSpFl26vabhywtO43JY5:UUMSt5 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93136d01d3137d2f |
|
VISUAL
aHash
|
001f0f2e2e0f01ff |
|
VISUAL
dHash
|
dcbf3cdcdcb8f700 |
|
VISUAL
wHash
|
000f0f3f2f0f01ff |
|
VISUAL
colorHash
|
00003400400 |
|
VISUAL
cropResistant
|
fdb77cdcdcb9f700,dcbd7cdcdc3cb33f,2caa5155367152b3,68000012120c11d4 |
โข Threat: Phishing
โข Target: Potential investors
โข Method: Form-based data theft
โข Exfil: https://equinoxisdriveaiupdates.org/assets/submit.php
โข Indicators: Suspicious domain, form, obfuscated JS
โข Risk: High
The site uses a form to collect user's personal information (name, email) which is then likely used for malicious purposes.
Pages with identical visual appearance (based on perceptual hash)