Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11414D823125876264037D3D02065DF76F3B6BA9BFB63CB0047E887B676F9C4C640A56A |
|
CONTENT
ssdeep
|
1536:pHjxvvV2RjuUgQmTa3MZo+Hd1+E08uHZIErrTqCHNjXt1XDyKWPw+h+xlshwt0we:fvHOQO8uHZIErrTqCtjLlkRuIsm |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8ad6563623b254fc |
|
VISUAL
aHash
|
663818290100d901 |
|
VISUAL
dHash
|
cc31326b2b232b2b |
|
VISUAL
wHash
|
66bc98bd81b1db81 |
|
VISUAL
colorHash
|
38250001000 |
|
VISUAL
cropResistant
|
3232f3734d5dc9d5,fef3f3f6e6ccf0c1,cc31326b2b232b2b |
โข Threat: Cryptocurrency Investment Fraud
โข Target: Financial users
โข Method: Phishing landing page designed to capture credentials or financial data
โข Exfil: /send endpoint via obfuscated JS
โข Indicators: Generic 'NorevixPulses' branding, fake user reviews, fraudulent CTA
โข Risk: High
The site lures victims to sign up on a fake trading platform to steal account credentials or PII.
Users are prompted to deposit funds into the fake platform that are then stolen.