Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14782A5B2A1805E3741A7C2DAB661633E62D2878CD9CB164673FD870E4AE6F40FD26513 |
|
CONTENT
ssdeep
|
384:pJIIoeTcWz8olRHjHTobnnUJA1yeWgUx0yeWgUtM6tibl:pJIIkolRDwnEAJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c3cb383c3ec3c31c |
|
VISUAL
aHash
|
0078787677670000 |
|
VISUAL
dHash
|
90c0c2ccc6cece3e |
|
VISUAL
wHash
|
0070feff7f670600 |
|
VISUAL
colorHash
|
382020000c0 |
|
VISUAL
cropResistant
|
90c0c2ccc6cece3e |
• Ameaça: Fraude financeira/Golpe de investimento
• Alvo: Usuários de trading financeiro
• Método: Personificação de uma firma financeira falsa
• Exfil: Envio de formulário via JavaScript
• Indicadores: Domínio extremamente recente, jargão corporativo genérico
• Risco: Alto
The site lures users into an investment platform with vague, high-prestige language. It uses obfuscated scripts to protect its exfiltration mechanisms.
Users are directed to sign up or submit 'Node Inquiries' to harvest contact info.