Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FB6212F1D568A93714A7C1C26AA65F2B32F0454AE78B021643FD439C8FFAD51FE12A42 |
|
CONTENT
ssdeep
|
384:144AJl1r662pxfXs8yahf5BKC0zWUTQR4iEH0PFyaOoqyJC0bRe2+9S:144q462pxfXs8yahf5BKULEmtde2+s |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c6c078f8d91f2725 |
|
VISUAL
aHash
|
e076367fff3c0000 |
|
VISUAL
dHash
|
808cece0c0e8e0f0 |
|
VISUAL
wHash
|
e076367fff7c0000 |
|
VISUAL
colorHash
|
09007000000 |
|
VISUAL
cropResistant
|
a3a63c898ce1f1f0,a7cecc70f0b0a0cc,808cece0c0e8e0f0 |
⢠Threat: Phishing
⢠Target: Cryptocurrency users
⢠Method: Social engineering
⢠Exfil: Potentially varies, based on the site.
⢠Indicators: Recent domain, Obfuscated JavaScript, Unusual branding.
⢠Risk: High
The attackers are likely trying to lure users into connecting their wallets or entering sensitive information by impersonating an offer. The use of the dollar sign in the branding is suspect.
The site uses obfuscated Javascript to hide the true purpose and potential malicious code.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain