Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T156F22420741926B3037385C5F5323F86B6A3F74FD19A48916ABC518C0FE7CB1BA295B6 |
|
CONTENT
ssdeep
|
768:VfO15SgFYN2pf5sNFGsPRI5dQ4sd8TASLdibdR4MdL4+dzgEDDYZ5nBS8s8wYhm2:FO15SgFYN2pf5sNFGsPRI5dQ4sdMASLB |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8e0fc3e170bab878 |
|
VISUAL
aHash
|
ff00000000ffffff |
|
VISUAL
dHash
|
c1e0f83d0e2b2b29 |
|
VISUAL
wHash
|
ff00000000ffffff |
|
VISUAL
colorHash
|
06007000000 |
|
VISUAL
cropResistant
|
01c1e0e070f8fe7d,29002b2b2b291400,e0e070f8ff3d0e1f |
• Threat: Financial Impersonation Phishing
• Target: Investors/Users of 'Perpetual Capital Advisors'
• Method: Investment portal front-end
• Exfil: JavaScript-based form submission
• Indicators: Extremely recent domain registration, obfuscated code
• Risk: High - Data/Financial theft
The site lures users to register for an account to steal personal information and likely initiate a secondary 'investment' fraud phase.
Hides the exfiltration destination of the submitted form data.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain