Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BE63DE715207651FDB6386C5F7591B8AA2CB931AC7230C49FBE5831B9FCAD24BC2C624 |
|
CONTENT
ssdeep
|
768:+y70XwZpGlBYvxlarjsU9ZC6y8t/o+jsIhOevjgj9luZUHfO0InZ7LyydQN+sWnv:+y70DPF44xl5y44oX+pfrSSjXyHjF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ee299542c5b552ba |
|
VISUAL
aHash
|
fbd9d0f0d0f0ffff |
|
VISUAL
dHash
|
2333332325c52426 |
|
VISUAL
wHash
|
fb9080c0c0f0f7fe |
|
VISUAL
colorHash
|
07600200400 |
|
VISUAL
cropResistant
|
2333332325c52426,634d1d6e62f1f0f0,20962996d64a2140,989b5b91b94fc7d1,273c3c3e38310363 |
• Threat: Financial Investment Fraud
• Target: Retail Investors
• Method: Phishing/Investment Scam
• Exfil: JavaScript form submission
• Indicators: Obfuscated source code, generic financial templates
• Risk: High (Loss of personal/financial data)
Captures user credentials via registration/login forms for identity theft or further financial scams.
Attempts to lure users into depositing funds into a fraudulent account.