Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C67284B260405A3F42F7D2CDB6A1337FA1D24589E98A025153ED4F3E9AEBF10EC1651B |
|
CONTENT
ssdeep
|
384:1anIIoqYTtTcJkcTmV862ixTfxUfJtzlKJp:1anIIdYFcVm+62i/cS |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9ed5232631cd8e33 |
|
VISUAL
aHash
|
c0c0fc9c0d171303 |
|
VISUAL
dHash
|
040021313d2563ff |
|
VISUAL
wHash
|
c0f0fcdc0f1f0707 |
|
VISUAL
colorHash
|
38000000098 |
|
VISUAL
cropResistant
|
040021313d2563ff |
• Threat: Financial Fraud/Scam
• Target: Investors
• Method: Deceptive corporate landing page
• Exfil: JavaScript-based submission
• Indicators: Generic 'investment' buzzwords, no clear business identity
• Risk: High
The site acts as a facade for a potential fraudulent investment scheme, using professional language to lure victims into providing personal data or capital.
Use of obfuscated scripts to capture visitor interaction data for future phishing campaigns.