Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T176D2B571A1002A3F11ABD3C9B3A1F72EA1D3924DDB4A090183FD475D4BE7E91DE2356A |
|
CONTENT
ssdeep
|
768:1H9y5NyT4B9bEpQxggl4R3+OXxNZGP7sOy2+y9BH4crIe:c9bEpQAFXxN0P7sOy2+UBH4crIe |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fc18c387922cbc6d |
|
VISUAL
aHash
|
bf008083f7f3f3ff |
|
VISUAL
dHash
|
68b0363707274798 |
|
VISUAL
wHash
|
3f008083c7f3a1ff |
|
VISUAL
colorHash
|
07400018000 |
|
VISUAL
cropResistant
|
68b0363707274798 |
• Amenaza: Estafa de inversión/Generación de leads
• Objetivo: Usuarios financieros/cripto
• Método: Página de aterrizaje de marketing engañoso
• Exfil: Envío de formulario vía JS oculto
• Indicadores: Scripts ofuscados, promesas financieras genéricas
• Riesgo: Alto
Collects PII via form for fraudulent investment operators.
Uses document.write/unescape to obscure the destination of form data.