Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FCE2B732B100763B5197D3C9B3A2F71AA2E39249EB560406E2FDC3AD1BE3D54DA33516 |
|
CONTENT
ssdeep
|
768:7Sky5NjO3sPCbH/iNS7sOy2+y9BH4crIe:PuCAS7sOy2+UBH4crIe |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c363bc1ced2cc1a3 |
|
VISUAL
aHash
|
000000000000ffff |
|
VISUAL
dHash
|
92ccc8c2caccac00 |
|
VISUAL
wHash
|
0064fc70003cffff |
|
VISUAL
colorHash
|
310000001c0 |
|
VISUAL
cropResistant
|
088080024c888000,928cc8c2c2c8cc4c |
• Ameaça: Phishing / Coleta de dados
• Alvo: Credenciais de usuário e PII
• Método: Página de destino de plataforma de trading enganosa
• Exfil: Envio de formulário via JS oculto
• Indicadores: JS ofuscado, domínio .shop
• Risco: Alto
The site uses a deceptive landing page to entice users to register for non-existent trading services to capture PII.
Used to evade automated scanners and hide the destination of form data.