Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AD6267B250406E3B409383C5B3616B6F72D2934CC64F1A016BFD8B4E8EE7E50FE16956 |
|
CONTENT
ssdeep
|
192:IRwngL8vdIIdgagpez/6HZ1y1QOhceNdY5ITkHSKVE:X3FIIupez/6HZ1y1HhcGA+kvVE |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ccb33364c9cc7233 |
|
VISUAL
aHash
|
00023cbc18181000 |
|
VISUAL
dHash
|
de0eb0b2b2b03058 |
|
VISUAL
wHash
|
425ffffef8181800 |
|
VISUAL
colorHash
|
380000001c0 |
|
VISUAL
cropResistant
|
de0eb0b2b2b03058 |
• Threat: Financial Investment Fraud/Phishing
• Target: Investors/Crypto Users
• Method: Deceptive corporate landing page with JS-based data collection
• Exfil: Obfuscated JS form submission
• Indicators: Obfuscation detected, generic high-yield rhetoric
• Risk: High
The site likely prompts for registration to gather user emails and passwords for subsequent social engineering.
Uses obfuscated JS to execute background tasks on the visitor's device.