Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12FA3ED234219352B4437C2D130695B3BE1E6999FFEE709405EECCBFA2BFAC90741A519 |
|
CONTENT
ssdeep
|
1536:RtpR4nXBKpSpFl26vtTbuD5QAFdfjtqBV:pUMGTbuD5QAFdfjtqBV |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93136d09d3137d2d |
|
VISUAL
aHash
|
00070f2e6e0f01ff |
|
VISUAL
dHash
|
dcb77cdcdcb9f301 |
|
VISUAL
wHash
|
00070f2f7f0f01ff |
|
VISUAL
colorHash
|
00003400400 |
|
VISUAL
cropResistant
|
fd375cdcdcb9f701,dcbf7cdcdcfcbb77,d333178449152dac,1e472113161c3424,d8114d3332314541 |
โข Threat: Phishing
โข Target: Users seeking financial services
โข Method: Forms with obfuscated Javascript
โข Exfil: https://fluxor-beam-ai.com/assets/submit.php
โข Indicators: Unusual domain, Javascript obfuscation, form submission.
โข Risk: Moderate
The site attempts to collect PII (name, email) through a form and submit the information to an external server. JavaScript obfuscation is used to hide the malicious code.
The collected data is likely exfiltrated to a remote server. The obfuscated JavaScript aims to hide the exfiltration process.
Pages with identical visual appearance (based on perceptual hash)