Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A4E2C631A1042A3B42A341C5BB79578BB3D2C389DB930A1522FCC35D6FCAD94ED796D8 |
|
CONTENT
ssdeep
|
384:B0gPf6nrA14APsEBfJdHkcwtc2daatc2daHtc2daatc2daatc2daEbVmz4Dh8a+5:B0gPfZ4kBjCdWddnTTSKTMb8zq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c112ed1a65a655eb |
|
VISUAL
aHash
|
000c0000000cfff3 |
|
VISUAL
dHash
|
d8f8cad8d8b00b03 |
|
VISUAL
wHash
|
003e3e2e0c08fffb |
|
VISUAL
colorHash
|
0e2000001c0 |
|
VISUAL
cropResistant
|
08000b0b0303020b,ccf8b8cadad8d0b8,0000041a32b2324c,0010081032b232ca |
• Threat: Financial Investment Fraud
• Target: Financial services users
• Method: HYIP investment portal
• Exfil: JS-based form submission
• Indicators: Obfuscated code, generic 'Get Rich' messaging
• Risk: High
Uses a fraudulent investment login portal to capture user credentials for later manual exploitation.
Enticing users to deposit funds into a fake investment platform.