Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14F2350B21242496F8A8BD1E4F6556B5EE1CAD35BC6238C49F3F9C257DFC2C28EC15260 |
|
CONTENT
ssdeep
|
768:23VhsZW32XRM0JYCWY1KnaaPe1SnRdbMcdQxSWNkzNrzGNt9Zs+GPTnZwbbQNKhR:VKZqsBo |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e3ac3cc1dfc13c81 |
|
VISUAL
aHash
|
cb03037076606081 |
|
VISUAL
dHash
|
b20783cccccac061 |
|
VISUAL
wHash
|
ff0323777e706081 |
|
VISUAL
colorHash
|
38086000000 |
|
VISUAL
cropResistant
|
b20783cccccac061 |
• Threat: Phishing/Credential Harvesting
• Target: Financial services users
• Method: JS-based form submission with obfuscation
• Exfil: JavaScript-based external submission
• Indicators: Obfuscated JS code, form handlers
• Risk: High
The site uses a deceptive trading interface to entice users to provide their credentials via a custom form.
JS obfuscation is used to hide the destination of form data.