Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A1C282B06210103AA11B86D76F72672D32FBB2FEE97A0115E7FD4B949BE5D88EC13045 |
|
CONTENT
ssdeep
|
384:7WtqY+SAaEslgigU74CyZMwq/02o8ElRYXX2eBIZHR0VVnVGuxc+HYc1RcWVcPW:kAaEsR/yWwn2ElRYXX2eBwx85YwaW |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92922d6de99696e1 |
|
VISUAL
aHash
|
03646c6c4000007e |
|
VISUAL
dHash
|
96cdcd8d926cd4d4 |
|
VISUAL
wHash
|
47447c7e60047e7e |
|
VISUAL
colorHash
|
38400038000 |
|
VISUAL
cropResistant
|
e8dcb2cccda2e4e8,96cdcd8d926cd4d4 |
• Threat: Cryptocurrency airdrop phishing scam
• Target: Potential cryptocurrency investors interested in "PONKE"
• Method: Luring users with the promise of a free airdrop, potentially to steal wallet information or tokens.
• Exfil: Unknown, but likely targeting cryptocurrency wallets.
• Indicators: Newly registered domain (ponke.icu), domain does not match expected or known "PONKE" domains, promoting an airdrop.
• Risk: HIGH - Potential theft of cryptocurrency assets.
Pages with identical visual appearance (based on perceptual hash)