Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T144D29673B1106A3B0167C3C9F751E71AA6E3924DEB49090A53FC835D1BEBD50EE2352A |
|
CONTENT
ssdeep
|
768:oSzy5NIzclGbDJlgDPDao269ew87sOy2+y9BH4crIe:E2Jy9264L7sOy2+UBH4crIe |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c343f53a9838cdc5 |
|
VISUAL
aHash
|
002020000000ffff |
|
VISUAL
dHash
|
d8cbc3c8cdc98b00 |
|
VISUAL
wHash
|
64f370300401ffff |
|
VISUAL
colorHash
|
31000000e00 |
|
VISUAL
cropResistant
|
0080a00458988000,d8cbc3c2cccdc90b |
• Threat: Financial Lead Generation/Phishing
• Target: Unsuspecting users seeking trading platforms
• Method: Deceptive marketing landing page with credential collection
• Exfil: JavaScript-based submission
• Indicators: Obfuscated JS, .shop domain, generic trading claims
• Risk: High
Collects PII via a deceptive landing page promising high-tech trading automation.
Selling collected data to fraudulent brokers or phishing operators.
Pages with identical visual appearance (based on perceptual hash)