Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1711308202221735F6C330F79F385B06AC1AFD344EAA698ADF394525234D2974CB7799A |
|
CONTENT
ssdeep
|
768:6hFYLAn7n0NXuefT6nP8PJs1LGbPDPrPrAPLODPVPJFBD5EbQSFecnRiEQ5hQ2iq:6hFYLAn7n0JuefT6hGUOPTD5EbQSFeco |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b332cccc3333ccc6 |
|
VISUAL
aHash
|
efffc7c7c7ffefff |
|
VISUAL
dHash
|
1d160c8d8d1e1e5c |
|
VISUAL
wHash
|
01c3c7c7c7c3c387 |
|
VISUAL
colorHash
|
07006000000 |
|
VISUAL
cropResistant
|
1d160c8d8d1e1e5c,96f979f47833e4f4 |
โข Threat: Phishing
โข Target: Exodus users
โข Method: Impersonation via Gitbook
โข Exfil: Potentially user credentials, information entered into forms.
โข Indicators: Domain mismatch, Gitbook hosting, JavaScript obfuscation and form submission.
โข Risk: HIGH
The site likely attempts to harvest credentials by directing users to a fake login. The JavaScript obfuscation and form submission indicate an intention to capture entered data and transmit it.
Pages with identical visual appearance (based on perceptual hash)
Found 5 other scans for this domain