Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T124420D71A5A1B53742A392DA9B76933B33E1819BCA471B4163FD832C8FE7D01FC12952 |
|
CONTENT
ssdeep
|
192:f9AFef6X31WtEGqy1gD83XI2w3t6I4Q3BIzlObAqni:f9AFeSVWqGqr+IAqni |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f95947a6a4a389a9 |
|
VISUAL
aHash
|
000000ffffffffff |
|
VISUAL
dHash
|
2a30130710480e54 |
|
VISUAL
wHash
|
00000000ffffffff |
|
VISUAL
colorHash
|
07001c00000 |
|
VISUAL
cropResistant
|
000a0b2b0a000400,ab565a6b2b6a6b05,c09080aeb680a4c0,001632500c0e4454,0020303030121305 |
• Ameaça: Golpe de Investimento Financeiro
• Alvo: Investidores de varejo
• Método: Impersonação de empresa de investimentos
• Exfil: Credenciais e dados financeiros
• Indicadores: Reivindicações de ativos não verificadas
• Risco: Alto
The site lures victims into registering an account to 'invest'. Once they provide credentials, they are prompted to link wallets or send funds to a 'broker'.
Collecting emails and passwords for credential stuffing attacks.