Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AD6267B250406E3B409383C5B3616B6F72D2934CC64F1A016BFD8B4E8EE7E50FE16956 |
|
CONTENT
ssdeep
|
192:IRwngL8vdIIdgagpez/6HZ1y1QOhceNdY5ITkHSKVE:X3FIIupez/6HZ1y1HhcGA+kvVE |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ccb33364c9cc7233 |
|
VISUAL
aHash
|
00023cbc18181000 |
|
VISUAL
dHash
|
de0eb0b2b2b03058 |
|
VISUAL
wHash
|
425ffffef8181800 |
|
VISUAL
colorHash
|
380000001c0 |
|
VISUAL
cropResistant
|
de0eb0b2b2b03058 |
• Ameaça: Fraude de Investimento / Phishing
• Alvo: Investidores
• Método: Landing page enganosa com coleta de dados via JS
• Exfil: Submissão de formulário JS ofuscado
• Indicadores: Ofuscação detectada, retórica genérica de alto rendimento
• Risco: Alto
The site likely prompts for registration to gather user emails and passwords for subsequent social engineering.
Uses obfuscated JS to execute background tasks on the visitor's device.