Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T120D26232B1C4663F46A7C2C8B3206B2EB2D3838DDB9A595163F8439D0BD7E40DD5352A |
|
CONTENT
ssdeep
|
384:ge/GLS/bS7iRYTcR/mkiccuOkdgiWgVvLi7TKfeIYsOy2+y9BH4ciUIe:ge/GLS8IGdeA1KG7sOy2+y9BH4cLIe |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d272fc2a8d69c5c1 |
|
VISUAL
aHash
|
000000000000ffff |
|
VISUAL
dHash
|
1c0cc840cdcd9b00 |
|
VISUAL
wHash
|
00c6e0303507ffff |
|
VISUAL
colorHash
|
39000c000c0 |
|
VISUAL
cropResistant
|
0080800458988000,982c484849cdcd1b |
• Threat: Financial credential harvesting
• Target: Users seeking AI trading tools
• Method: Deceptive marketing landing page
• Exfil: Unknown backend (JS submission)
• Indicators: Obfuscated script, high-pressure registration form
• Risk: High
The site uses a 'Get Started' funnel to harvest PII for downstream financial fraud or cold-calling scams.
Uses obfuscated code to prevent simple security analysis of the form submission destination.