Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14B3331B22146193F958792CAAB74AB0DF1C7934BC6620C49F7F2834B9FC2D65FC19660 |
|
CONTENT
ssdeep
|
768:u9Z8fKZ8fPX8E5BvnFTtp+l4nhHiZ7viJBJBse+fZHzaDbcduhsty0gKIBKen8Qa:n57+Svk5+m |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bfbc5e40d8416371 |
|
VISUAL
aHash
|
12ffffffff000000 |
|
VISUAL
dHash
|
34264e5667ccc445 |
|
VISUAL
wHash
|
02bfffffff000000 |
|
VISUAL
colorHash
|
1e400018000 |
|
VISUAL
cropResistant
|
36366e4e5e5776af,4b94946464142262,172f6f3fbf7d3739,26ccc8c4c9e44549 |
• Threat: Financial phishing/Investment scam
• Target: Financial services users
• Method: Generic trading platform facade
• Exfil: JavaScript-based submission
• Indicators: Obfuscated JS code, generic content
• Risk: High
User is prompted to sign up for a fake investment account to capture PII and login credentials.
Luring users into depositing funds into a fraudulent investment account.