Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EC42A9329860AB7B11F392D563311B5A63C2928BDD330A4ABFF48B1D5FDAD45CD92205 |
|
CONTENT
ssdeep
|
96:TQdBergD1fXKyII03Km0AXxAX11QhIzedIT05bOR7XMBIwgIDINIZIaI7sXyQwWe:IBerb8035xsuyjw/6nN |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8d6de82dbc68e8a4 |
|
VISUAL
aHash
|
c30000080000ffff |
|
VISUAL
dHash
|
2bfa92b0f670fa20 |
|
VISUAL
wHash
|
ff00001c1e08ffff |
|
VISUAL
colorHash
|
1a000400200 |
|
VISUAL
cropResistant
|
23332b2b2b2b3323,e60080b0b430003b,20c0c8c8c84020c0,fb7ad6b0f2f472fa |
• Threat: Investment Fraud
• Target: Retail Investors
• Method: Financial phishing/SCAM
• Exfil: Unknown backend
• Indicators: Obfuscation, no regulation
• Risk: High
Platform lures users to register to gain access to fake investment portfolios, later requesting deposits.
Uses obfuscated JS to evade simple static analysis of the registration process.