Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1903245B250026A3F86E7D2D6F661236EE2938685DAC7194A73FE4F0F4AC6F80DC05517 |
|
CONTENT
ssdeep
|
192:A64/JQQfTUMexYrUjUEX++uEnNbIIoXzhfaFm6rgFSIxyqWokU6lnQ9AORwHN5:8eIIoXAcwJEWokU6xAHRwHN5 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e61d9962246ecd33 |
|
VISUAL
aHash
|
ff070783c1e0e5ff |
|
VISUAL
dHash
|
231f2f074d0d0b03 |
|
VISUAL
wHash
|
ff030303c1e0e1ff |
|
VISUAL
colorHash
|
07200030000 |
|
VISUAL
cropResistant
|
231f2f074d0d0b03 |
• Amenaza: Fraude Financiero/Estafa de Inversión
• Objetivo: Inversores/Público General
• Método: Página de aterrizaje con marketing engañoso y scripts ofuscados
• Exfil: Envío de formularios mediante JavaScript
• Indicadores: Retórica de alto impacto, ofuscación técnica
• Riesgo: Alto
The site acts as a lead generation funnel for potential investment scams, utilizing obfuscated code to prevent analysis of the destination endpoints.
Uses obfuscated JS to collect user interaction data.