Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DF6308BC42521A8EB03BC5C7BA61BB2CC131538ADF770DD9F6E63022D7DD86901A55B8 |
|
CONTENT
ssdeep
|
768:MRJnTAR3scHoRdXXFTo0g4ZrS/nTAR3s/yyCbLjQWBf4H4QVgU:MrTNGudnmMm/TNYkWBWn |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cb25359e39bc2613 |
|
VISUAL
aHash
|
032020787c3c3c08 |
|
VISUAL
dHash
|
3a4ac9f2e9e9783a |
|
VISUAL
wHash
|
03206878fcfebe1c |
|
VISUAL
colorHash
|
31000000000 |
|
VISUAL
cropResistant
|
cb8b2b2b2b2babcd,9811333a9cc4569b,f25654542c5a928a,f08094373380a2f0,3a4ac9f2e9e9783a |
• Amenaza: Recolección de credenciales / Phishing
• Objetivo: Usuarios generales
• Método: Formulario con JS ofuscado
• Exfil: Backend desconocido
• Indicadores: Ofuscación, branding genérico
• Riesgo: Alto
The site uses obfuscated JavaScript to capture input data when users interact with CTA buttons or forms.
Uses vague, pseudo-professional terminology to build false trust.