Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CCF27531A251AE3B44A792E5F3B5636F32D2938AC942024583FC83BD0BEBDD4FD26554 |
|
CONTENT
ssdeep
|
768:L4arx4uDXIeabjq9AoAV9AvphCg0uf/bUiKDGMn:LXDXIecuf/bU1KMn |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
be2ac1eb5f2a490a |
|
VISUAL
aHash
|
8987878f8ff3f3fe |
|
VISUAL
dHash
|
2b0d3d392dc70726 |
|
VISUAL
wHash
|
8187078785e1f1fe |
|
VISUAL
colorHash
|
070010001c0 |
|
VISUAL
cropResistant
|
2b0d3d392dc70726 |
• Ameaça: Golpe de investimento em criptomoedas
• Alvo: Investidores de varejo
• Método: Representação de plataforma de trading com IA
• Exfil: Endpoint /create_lead/
• Indicadores: JS ofuscado, design padrão de portal de investimento
• Risco: Perda financeira através de depósitos fraudulentos
The site solicits user PII via a lead-gen form to facilitate follow-up social engineering attacks.
Uses encoded payloads to hide where data is being transmitted.