Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T143F27431A255AE3B40A792E5F3A5632F32E2D289C946024583FD83BD0FFBD84FD22554 |
|
CONTENT
ssdeep
|
768:rZEElJarxsLDXIeawjq9AoAV9AvphCg0uf/bU7KZm+ho:ryElXDXIeJuf/bU+kF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9eaa416adf6ac12a |
|
VISUAL
aHash
|
f9ff9f9f9fff0000 |
|
VISUAL
dHash
|
2b7c3d392dcd07c0 |
|
VISUAL
wHash
|
b91f0f8f8ce000fe |
|
VISUAL
colorHash
|
07200038000 |
|
VISUAL
cropResistant
|
2b783d39292d4d07,0707070202c0c4c4,0000004448000000 |
• Ameaça: Fraude de Investimento
• Alvo: Usuários financeiros
• Método: Plataforma de trading genérica
• Exfil: Endpoint /create_lead/
• Indicadores: JS ofuscado, falta de rastro corporativo
• Risco: Alto
Captures user contact details via landing page forms to sell to fraudulent investment call centers.
Uses professional financial terminology to gain victim trust.