Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19AA37A33411875274437C6D430A95B3BE2E69A8FFA970A014EECD7FA1BFAC60745B11A |
|
CONTENT
ssdeep
|
1536:dO8EnLz4NP/y9svbliCd3oLUSTuFFtWAuCa25X2ZP4:M8ELmAMoLUSTuu4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c343bd1abc38c533 |
|
VISUAL
aHash
|
00200000000000ff |
|
VISUAL
dHash
|
79c9c0c8c9c0d388 |
|
VISUAL
wHash
|
007460607478ffff |
|
VISUAL
colorHash
|
31000c00000 |
|
VISUAL
cropResistant
|
0000000118588090,19c9c8c0c9c9c052 |
โข Threat: Lead Harvesting / Phishing
โข Target: Financial/Educational Users
โข Method: Obfuscated JS form submission
โข Exfil: /api/lead
โข Indicators: Obfuscation detected in client-side script
โข Risk: Moderate
The site collects user PII under the guise of an educational program to sell leads to third parties.
Uses encoding techniques to prevent automated security analysis of the data submission process.