Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T171036070A4A09D3A058382E1F7F2E759136DE282CE0106F553ED475F5BE6E9CAB4F209 |
|
CONTENT
ssdeep
|
384:s9aMxHwjWzXIqz/bgdqKijdfUC5d6PtlXghIgFpuhQgghX:maMxHM8XIqTbgSUCjrFpuhViX |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cccd2231aa47aedc |
|
VISUAL
aHash
|
80183c38180000ff |
|
VISUAL
dHash
|
47b2717232303001 |
|
VISUAL
wHash
|
993c3c3c3c1818ff |
|
VISUAL
colorHash
|
38e00000001 |
|
VISUAL
cropResistant
|
47b2717232303001 |
โข Threat: Financial Investment Fraud
โข Target: Retail Investors
โข Method: Lead harvesting through deceptive 'bonus' claims
โข Exfil: Form submission to backend
โข Indicators: Obfuscated JS code, vague trading promises
โข Risk: High
The site lures users with 'bonuses' to collect contact information, which is then passed to offshore call centers for investment fraud.
Uses standard web encoding to bypass automated security filters.