Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A28265F6E1165A3B45F3C1D2B3B2133AB2E1818DCA92460927FD471D07E9E45FC2786A |
|
CONTENT
ssdeep
|
384:+gS44ouCc4BmOrXP+W8rF+0IiP+W8rF+0IFv9LlSTij/u:DS44mcITP+W8rF+0IiP+W8rF+0IFfSma |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c33c69d394c31c73 |
|
VISUAL
aHash
|
0000027f7e7e6000 |
|
VISUAL
dHash
|
dc1ccec4ccc8c0f0 |
|
VISUAL
wHash
|
000227ffffff7000 |
|
VISUAL
colorHash
|
30002400000 |
|
VISUAL
cropResistant
|
dc1ccec4ccc8c0f0 |
• Amenaza: Fraude de Inversión
• Objetivo: Inversores minoristas
• Método: Sitio de phishing de trading por IA
• Exfil: Captura de formulario JavaScript
• Indicadores: Reclamaciones financieras poco realistas
• Riesgo: Alto
Uses a deceptive landing page to capture user interest for a fraudulent investment scheme.
Misappropriates an existing corporate name to build false credibility.