Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1697228F1513189A965078BACDB33715CA33730F8AF2881C1E2E486596281CF6CDB79D5 |
|
CONTENT
ssdeep
|
384:fnjIx4X7ePMSq7ZQm6ishM23ewpT7/8boFA:fnjlePMfQwwpv/IoFA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
932c64c39b6ce31e |
|
VISUAL
aHash
|
6000000c0c6c002c |
|
VISUAL
dHash
|
d000041ad9d822dc |
|
VISUAL
wHash
|
60600c0cccec0a7e |
|
VISUAL
colorHash
|
38e00000000 |
|
VISUAL
cropResistant
|
d000041ad9d822dc |
• Threat: Phishing targeting cryptocurrency users.
• Target: Users of Espresso blockchain.
• Method: Impersonating Espresso to steal wallet credentials.
• Exfil: Data exfiltration via obfuscated JavaScript using potentially atob, eval, and fromCharCode.
• Indicators: New domain, domain mismatch, obfuscation, and lack of login form.
• Risk: HIGH - Potential credential theft for crypto wallets.