Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F632A57550847D37869392C8F772E31FF2C286C496A78761F2FC8B1E5AC4EA6CC19119 |
|
CONTENT
ssdeep
|
192:shApUHOizof4mU+yL10loAc1Adu0AoWt5:GAnizof4mUjLmNdu9oA5 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8b29b569da4bcad0 |
|
VISUAL
aHash
|
ff011901000000ff |
|
VISUAL
dHash
|
ebebe3e3e3e3cbcd |
|
VISUAL
wHash
|
ff031911313129ff |
|
VISUAL
colorHash
|
07e00000000 |
|
VISUAL
cropResistant
|
2bebebcbebf3f3eb,1a128e4e464d4b8a,cdcbcbcb00800000,cbfbe3ebe3e3cbcb |
• Threat: Financial Investment Phishing
• Target: Financial credentials/Investor funds
• Method: Deceptive landing page with JS-based data exfiltration
• Exfil: JavaScript form hijacking
• Indicators: Newly registered domain, code obfuscation
• Risk: High
The site uses a landing page to lure users into providing contact details or funds, then utilizes obfuscated scripts to transmit that data to an attacker-controlled server.
Uses professional financial aesthetics to build false trust.