Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T156F22420741926B3037385C5F5323F86B6A3F74FD19A48916ABC518C0FE7CB1BA295B6 |
|
CONTENT
ssdeep
|
768:VfO15SgFYN2pf5sNFGsPRI5dQ4sd8TASLdibdR4MdL4+dzgEDDYZ5nBS8s8wYhm2:FO15SgFYN2pf5sNFGsPRI5dQ4sdMASLB |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8e0fc3e170bab878 |
|
VISUAL
aHash
|
ff00000000ffffff |
|
VISUAL
dHash
|
c1e0f83d0e2b2b29 |
|
VISUAL
wHash
|
ff00000000ffffff |
|
VISUAL
colorHash
|
06007000000 |
|
VISUAL
cropResistant
|
01c1e0e070f8fe7d,29002b2b2b291400,e0e070f8ff3d0e1f |
• Amenaza: Fraude de Inversión Financiera
• Objetivo: Inversores minoristas
• Método: Suplantación de firma de inversión para capturar datos
• Exfil: Envío de formularios mediante JS
• Indicadores: Dominio extremadamente nuevo, ofuscación sospechosa
• Riesgo: Alto
The site lures users into 'investing' funds into a fake brokerage platform. JavaScript obfuscation is used to hide the data submission process.
The 'Open Account' link likely leads to a registration form designed to steal PII and financial login details.
Pages with identical visual appearance (based on perceptual hash)