Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1975284F65055A93B82B7C2D6B726233E92E356CDC6C7150167FCCB5A09E2F82FC22815 |
|
CONTENT
ssdeep
|
192:rzQ8PFM9ubfm62i44B+duHlcDlxHPlURA8oko9/I9oT4s54n751bAjGKkRS:fPC9ubeQ44l6RxHPlAokoBioT7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8c9f736449db4c61 |
|
VISUAL
aHash
|
000f3f3f1e186c60 |
|
VISUAL
dHash
|
f8fcf0f0f0b0c888 |
|
VISUAL
wHash
|
001f3f3f1e1c7c68 |
|
VISUAL
colorHash
|
38000000038 |
|
VISUAL
cropResistant
|
f8fcf0f0f0b0c888 |
• Threat: Financial/Investment Phishing
• Target: Users seeking crypto/enterprise investment
• Method: High-quality deceptive template with hidden exfil JS
• Exfil: JavaScript-based form collection
• Indicators: Domain created 12 days ago
• Risk: High
Uses a professional landing page to lure users into providing information via forms.
JavaScript obfuscation hides the destination of user-entered data.