Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16D2274A45A68412133ABCBADB06467ECB3A7614FC7339054F2D8978093CAFFDCD55601 |
|
CONTENT
ssdeep
|
96:yQrCSdlqdkBNsWziehhe9lCdy+JuVlQK74fLGv33MgRj+xGrcUQOFEcyMZ8TVm2V:frsdCiebi0I3lj+Mocfk7yQ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
89ab23ab89ab8d8d |
|
VISUAL
aHash
|
0100181818180000 |
|
VISUAL
dHash
|
130030b232301000 |
|
VISUAL
wHash
|
438399583fbf158c |
|
VISUAL
colorHash
|
382c0000003 |
|
VISUAL
cropResistant
|
130030b232301000 |
• Threat: Cryptocurrency pre-sale scam phishing
• Target: Users interested in buying the $GROK cryptocurrency
• Method: Fake pre-sale website stealing SOL cryptocurrency
• Exfil: Unknown, likely sent directly to attacker's wallet
• Indicators: New domain, brand impersonation, claims to be associated with Elon Musk
• Risk: CRITICAL - Immediate cryptocurrency theft
Pages with identical visual appearance (based on perceptual hash)