Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12303953411859EBF119382E4F366EB6BF298D740C927DA57E3F9832A1BC6C40DE61364 |
|
CONTENT
ssdeep
|
384:pOw6U/SAl4HI0NJ2TCuTCm6X6tOSQmdBHFIi7/srJby9Nxjt9iPB4:oxeTCuTCNqcSQndUx5P |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ca16e9e91469b671 |
|
VISUAL
aHash
|
0000040410fff9ff |
|
VISUAL
dHash
|
c4ccecaca4331373 |
|
VISUAL
wHash
|
00000404fcffffff |
|
VISUAL
colorHash
|
1b206008000 |
|
VISUAL
cropResistant
|
c4c443a080688080,808080e868e08080,8080801a3a808080,a000a8ecaca88080,00244a6969600640,0033331333135378,94ccc4ecececa4a3,b0f0f061e5b339ba |
โข Threat: Phishing
โข Target: Unsuspecting users
โข Method: Deception using a fake trading platform
โข Exfil: User credentials and personal data (email, name, etc.) via form submission
โข Indicators: Domain age, Javascript obfuscation, form actions, and brand impersonation
โข Risk: High
The attacker aims to collect user credentials (name, email) through a fake registration form. This data can be used for identity theft, fraud, or to launch other attacks.
Pages with identical visual appearance (based on perceptual hash)