Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10163B67012335AAB01A383D1E6B79B5991C49390E7638B69E3FC8B5F9ECEC44EC45162 |
|
CONTENT
ssdeep
|
768:e2ZELk+CunziAeYNMM+142Wmf7n4h3MC0hEEn63xxO87F:f+CwWAeYNMM+142Wmf7xn6hxO87F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bad5aca890e6c0eb |
|
VISUAL
aHash
|
ff00e4ee4d818181 |
|
VISUAL
dHash
|
4c094d4c9909250b |
|
VISUAL
wHash
|
ff00f4fecf818181 |
|
VISUAL
colorHash
|
300000082c0 |
|
VISUAL
cropResistant
|
0f0f0f09490f0f0f,c6194c4c9909251b |
• Threat: Cryptocurrency phishing aiming to harvest credentials or wallet information.
• Target: Users interested in cryptocurrencies, especially those using CoinMarketCap.
• Method: The site uses a fake landing page to lure users, likely redirecting to a wallet connection or other forms to steal information.
• Exfil: Unknown, likely a custom API or Telegram.
• Indicators: Recently created domain (11 days), domain name does not match the brand, obfuscated JavaScript, indicating malicious intent.
• Risk: HIGH - potential for immediate financial loss and data compromise.
Pages with identical visual appearance (based on perceptual hash)