Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C3C32F707E136826206F61DF9227570E62C0C7C9EAA36BE522F4D3289BF5C50BFA7115 |
|
CONTENT
ssdeep
|
1536:+EHkgntbKpD3IG8QwW3WG96wW3nGRqwW3MG+XjwW3rG+st7yBftj5gVw93NGlD3C:mLhwD/xaz8xJys6k8MMN |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8762980bfce7ccc2 |
|
VISUAL
aHash
|
ff00000020203fff |
|
VISUAL
dHash
|
73d9c64ecec3d932 |
|
VISUAL
wHash
|
ff000020323f3fff |
|
VISUAL
colorHash
|
07006000040 |
|
VISUAL
cropResistant
|
2003292b2b9100d2,7273725a4d921565,0989694d5da989a9,e8eef20080323232,58d9c64ecec5dbf8 |
• Threat: Investment Scam
• Target: Investors
• Method: Fake financial services portal
• Exfil: Form submission/Credential harvesting
• Indicators: Obfuscated JS code, generic investment theme
• Risk: High
Uses a fake investment portal to entice users to sign up and submit personal/financial data.
Uses obfuscation to evade static security analysis while loading data-stealing payloads.