Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T173F3662302186A2E4437C3D175759B76D2B6D98BFAA30A404FDCC7B637EAC50B81B65C |
|
CONTENT
ssdeep
|
1536:9YtUgQmTa3MZo+Hd1+w0Q1jjC3lemF9YYsQOVax0882WRfsSy/:9YtOQ2b3tvYhWW8822ty/ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c61be4bb2d83932c |
|
VISUAL
aHash
|
fd1c1c3811bff3f3 |
|
VISUAL
dHash
|
19b4fcf1632a2727 |
|
VISUAL
wHash
|
fd1c1c100197f3f3 |
|
VISUAL
colorHash
|
07000180003 |
|
VISUAL
cropResistant
|
19b4fcf1632a2727,0000808880c80000 |
• Amenaza: Phishing de inversión financiera
• Objetivo: Usuarios interesados en plataformas de trading
• Método: Suplantación de una firma de trading con IA
• Exfil: Formulario enviado a /send
• Indicadores: JS ofuscado, dominio sospechoso
• Riesgo: Alto
The site uses a deceptive form to capture PII from victims under the guise of an investment registration process.
The site requests name, email, and phone, likely for targeted secondary phishing attacks or data selling.