Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15E139571E0147D3B019392E5E7326BAFA3C48245CA130755A3FC9B6DAFD7E94DC2A248 |
|
CONTENT
ssdeep
|
384:tUB44MlezI4OE52xLKIhQtaSc4aaTLSf0rQyjFuBIcesHfft:eB44RzIPlxLKI2gSc45TLScrpjFnkF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec3e93cb962861b1 |
|
VISUAL
aHash
|
9f9f8191d1f1f9fe |
|
VISUAL
dHash
|
2b36333737030304 |
|
VISUAL
wHash
|
17138191f0f0f8fe |
|
VISUAL
colorHash
|
07000000c41 |
|
VISUAL
cropResistant
|
2b36333737030304 |
• Amenaza: Fraude de Inversión Financiera
• Objetivo: Inversores minoristas
• Método: Recolección de credenciales
• Exfil: JS ofuscado/Hook remoto
• Indicadores: Código fuente ofuscado, dominio reciente
• Riesgo: Alto
The site mimics a legitimate trading platform to deceive users into entering their credentials, which are captured via obfuscated JS.
Platform uses fake 'Copy Trading' promises to lure users into depositing funds into non-existent accounts.