Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EE92C331A150263F1263C3D9B761B72EA0D382CDDB46181542FC4B9E9BDBF90CE2756A |
|
CONTENT
ssdeep
|
384:KtGpy5NqogUur2lhoesMNv0fmg6xKQnKjxq4ObDbmnz3nIYsOy2+y9BH4cUUIe:lpy5NqAnv0d6xKQnWxq4ObDbmz37sOy8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c343fd3a9829929e |
|
VISUAL
aHash
|
002020000000ffff |
|
VISUAL
dHash
|
9cc8c0c3cccc9300 |
|
VISUAL
wHash
|
00f07070240fffff |
|
VISUAL
colorHash
|
39001000180 |
|
VISUAL
cropResistant
|
100c32b2b2300800,0080800270908000,9cc8c0c8c3ccccc3 |
• Threat: Credential/PII Harvesting
• Target: Financial users
• Method: Fake AI trading platform
• Exfil: JavaScript-based submission
• Indicators: Obfuscated JS code
• Risk: High
Uses a professional-looking interface to lure users into registering, harvesting PII for lead generation or direct financial theft.
Hides submission endpoints and exfiltration logic within obfuscated scripts to evade automated analysis.