Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C3C32F707E136826206F61DF9227570E62C0C7C9EAA36BE522F4D3289BF5C50BFA7115 |
|
CONTENT
ssdeep
|
1536:+EHkgntbKpD3IG8QwW3WG96wW3nGRqwW3MG+XjwW3rG+st7yBftj5gVw93NGlD3C:mLhwD/xaz8xJys6k8MMN |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8762980bfce7ccc2 |
|
VISUAL
aHash
|
ff00000020203fff |
|
VISUAL
dHash
|
73d9c64ecec3d932 |
|
VISUAL
wHash
|
ff000020323f3fff |
|
VISUAL
colorHash
|
07006000040 |
|
VISUAL
cropResistant
|
2003292b2b9100d2,7273725a4d921565,0989694d5da989a9,e8eef20080323232,58d9c64ecec5dbf8 |
• Amenaza: Estafa de inversión
• Objetivo: Inversores
• Método: Portal de servicios financieros falsos
• Exfil: Envío de formularios / robo de credenciales
• Indicadores: Código JS ofuscado, tema de inversión genérico
• Riesgo: Alto
Uses a fake investment portal to entice users to sign up and submit personal/financial data.
Uses obfuscation to evade static security analysis while loading data-stealing payloads.