Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E633723760046A7B128386C6B7753B6FA3DAD244E7574A2667F8E30C07DBE81CD31962 |
|
CONTENT
ssdeep
|
768:9LCjSkL+IOSZXFzrXFCaBQCU4onDYsAJxTOpJuJ5OaRlahxq:YmkL+IzB7QHn7AOpJuJ5OaR8I |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f66cc93f9134c229 |
|
VISUAL
aHash
|
f0f0f0c6868686fc |
|
VISUAL
dHash
|
6427242c2c2c2c91 |
|
VISUAL
wHash
|
f0f0f0e6868686fc |
|
VISUAL
colorHash
|
03000008030 |
|
VISUAL
cropResistant
|
61311333233333c8,04d8c6c474247058,6427242c2c2c2c91 |
⢠Threat: Phishing
⢠Target: Cryptocurrency traders/users
⢠Method: Impersonation and credential harvesting
⢠Exfil: Data from registration form
⢠Indicators: Suspicious domain, registration form, urgency.
⢠Risk: High
The attacker aims to steal user credentials by creating a fake login/signup form that looks like a crypto platform.
Pages with identical visual appearance (based on perceptual hash)