Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A4E2C631A1042A3B42A341C5BB79578BB3D2C389DB930A1522FCC35D6FCAD94ED796D8 |
|
CONTENT
ssdeep
|
384:B0gPf6nrA14APsEBfJdHkcwtc2daatc2daHtc2daatc2daatc2daEbVmz4Dh8a+5:B0gPfZ4kBjCdWddnTTSKTMb8zq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c112ed1a65a655eb |
|
VISUAL
aHash
|
000c0000000cfff3 |
|
VISUAL
dHash
|
d8f8cad8d8b00b03 |
|
VISUAL
wHash
|
003e3e2e0c08fffb |
|
VISUAL
colorHash
|
0e2000001c0 |
|
VISUAL
cropResistant
|
08000b0b0303020b,ccf8b8cadad8d0b8,0000041a32b2324c,0010081032b232ca |
• Amenaza: Fraude de inversión financiera
• Objetivo: Usuarios de servicios financieros
• Método: Portal de inversión HYIP
• Exfil: Envío de formularios mediante JS
• Indicadores: Código ofuscado, mensajes genéricos de riqueza
• Riesgo: Alto
Uses a fraudulent investment login portal to capture user credentials for later manual exploitation.
Enticing users to deposit funds into a fake investment platform.