Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D682FB31309121770A7384DAE6267F4AA2F3F34FC2A958526AFD87800FE3DB5B815671 |
|
CONTENT
ssdeep
|
192:apuKaiZDLNJ6aOfyHmE1DAflcCMU7GmNNSjivuSnPyyuMNC8LLM2:ETOqH9Asc/N4j+PyydNCaR |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ef0a92924f6bc21e |
|
VISUAL
aHash
|
390f91f1b1fffbff |
|
VISUAL
dHash
|
613b232323011b3b |
|
VISUAL
wHash
|
390511f191ff9387 |
|
VISUAL
colorHash
|
07200018200 |
|
VISUAL
cropResistant
|
613b232323011b3b |
• Ameaça: Coleta de credenciais financeiras
• Alvo: Investidores
• Método: Personificação de plataforma de investimento
• Exfil: Envio de formulário baseado em JS
• Indicadores: JS ofuscado, alegações financeiras genéricas
• Risco: Alto
The site acts as a landing page for collecting credentials from users interested in high-yield investments.
JS hooks capture form input during the sign-up process.