Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B713D83148CC2A7B629352C4F310665FE395C144FBBACA49E2EA8B9F07C6D54CC27A5D |
|
CONTENT
ssdeep
|
768:5+aF14yitLLGzledahyFZzwTFSTr0tO/PH3SU/b64nK0XFB1HOXgr1:5+aF11i1LGzlbsFZzwZ2rAO/KVAr1HOk |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9416ebcac9caca96 |
|
VISUAL
aHash
|
fd0606060606fffb |
|
VISUAL
dHash
|
71ccccececfc3b33 |
|
VISUAL
wHash
|
fd0606060606fffb |
|
VISUAL
colorHash
|
0e0000001c0 |
|
VISUAL
cropResistant
|
0001096161890152,96d6e8b094710f8e,8038330c33133313,ccccccccccececec,5d8ba6decec6c647 |
• Threat: Phishing
• Target: Individuals interested in crypto trading
• Method: Impersonation and credential harvesting
• Exfil: Potentially email or other methods.
• Indicators: Domain, JavaScript, suspicious content
• Risk: HIGH
The attacker is attempting to gather user credentials and personal information by posing as a legitimate crypto-related service.
The attacker uses the theme of crypto trading to entice users to provide their information.
Pages with identical visual appearance (based on perceptual hash)