Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T120D26232B1C4663F46A7C2C8B3206B2EB2D3838DDB9A595163F8439D0BD7E40DD5352A |
|
CONTENT
ssdeep
|
384:ge/GLS/bS7iRYTcR/mkiccuOkdgiWgVvLi7TKfeIYsOy2+y9BH4ciUIe:ge/GLS8IGdeA1KG7sOy2+y9BH4cLIe |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d272fc2a8d69c5c1 |
|
VISUAL
aHash
|
000000000000ffff |
|
VISUAL
dHash
|
1c0cc840cdcd9b00 |
|
VISUAL
wHash
|
00c6e0303507ffff |
|
VISUAL
colorHash
|
39000c000c0 |
|
VISUAL
cropResistant
|
0080800458988000,982c484849cdcd1b |
• Amenaza: Cosecha de credenciales financieras
• Objetivo: Usuarios buscando herramientas de trading con IA
• Método: Landing page de marketing engañosa
• Exfil: Backend desconocido
• Indicadores: Script ofuscado, formulario de registro
• Riesgo: Alto
The site uses a 'Get Started' funnel to harvest PII for downstream financial fraud or cold-calling scams.
Uses obfuscated code to prevent simple security analysis of the form submission destination.