Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16AA2A436A0142A3F519383CDB361FB2EE1E35249D789180A63FD475E8BD7E90CD2752A |
|
CONTENT
ssdeep
|
384:FGxYy5NO1zsRXdKsx1ggBCuvw7WfcdmZYrEe8+lv5Q4lKzxIYsOy2+y9BH4cCUIe:FiYy5NOSqoCuvw7Uc0ZYrEe8+lhQ4lKL |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9202ed69935f9593 |
|
VISUAL
aHash
|
00002e2e0e00f1ff |
|
VISUAL
dHash
|
9fcdcccccc4c4300 |
|
VISUAL
wHash
|
00213e3e0e04ffff |
|
VISUAL
colorHash
|
32000000cc0 |
|
VISUAL
cropResistant
|
4766667862444d4d,4080800030908000,9dc7cccccccc6c43 |
• Amenaza: Phishing de inversión financiera
• Objetivo: Credenciales financieras/PII
• Método: Landing page de plataforma de trading engañosa
• Exfil: Envío de formulario mediante JavaScript
• Indicadores: Dominio reciente, ofuscación
• Riesgo: Alto
The site collects user personal information under the guise of an investment service to perform financial fraud.
Uses obfuscated JS to send collected form data to external servers.