Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T110D1AA386309092EE683C3F8F792B73A527C42DBDF1B4198F2A841755349E56EE27174 |
|
CONTENT
ssdeep
|
96:nEfQOLAhRYBJqExQFdNVkU1V1VMIRhVUkhSk8EyLkmgdyPku+3tPkOT/:EfJAhR0BxUNfJfRhi6S+kmdyPP+3tPlb |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c99866d689a627d9 |
|
VISUAL
aHash
|
7c181a5a18207620 |
|
VISUAL
dHash
|
f0b2b2b2b2d4c4c4 |
|
VISUAL
wHash
|
7e581a5a782afe22 |
|
VISUAL
colorHash
|
30600018000 |
|
VISUAL
cropResistant
|
f0b2b2b2b2d4c4c4 |
• Threat: Cryptocurrency phishing kit
• Target: Pump.fun and Padre users
• Method: Fake rewards site asking users to connect wallets
• Exfil: Potential wallet data theft
• Indicators: Newly registered domain, obfuscated JavaScript
• Risk: HIGH - Immediate wallet compromise
Pages with identical visual appearance (based on perceptual hash)