Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T134C281B06210103AA11B86D76F72672D32FBB2FEE9760115E7FD4B949BE5DC8E813440 |
|
CONTENT
ssdeep
|
384:7WtqY+SAaEslgigU74CyZMwq/02o8ElRYXX2RwZHR0VVnVGuxc+HYc1RcWVcAf:kAaEsR/yWwn2ElRYXX2RIx85YwZf |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92922d6de99696e1 |
|
VISUAL
aHash
|
03646c6c4000007e |
|
VISUAL
dHash
|
96cdcd8d9268dcd4 |
|
VISUAL
wHash
|
47447c7e60047e7e |
|
VISUAL
colorHash
|
38400038000 |
|
VISUAL
cropResistant
|
e8dcb2cccda2e4e8,96cdcd8d9268dcd4 |
• Threat: Cryptocurrency airdrop phishing
• Target: Users interested in Ponke cryptocurrency
• Method: Luring users with the promise of free Ponke tokens through an airdrop
• Exfil: Unknown, likely aiming for crypto wallet access or personal information
• Indicators: New domain, domain mismatch, use of 'airdrop' term
• Risk: MEDIUM - Potential for wallet compromise or personal data theft
Pages with identical visual appearance (based on perceptual hash)