Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10813C83104C46B2B55E343D5A310DA4BE39582C4E376D94BF1EA831A67D5F8ACC2BB9C |
|
CONTENT
ssdeep
|
768:tdz5UkPiUTidCNyiOC+Mr9YlM8cIJ2rkFJcx8rTAwuD/amO/351Jir7TknSClGJj:lUkPiGiq/F9YlTcIJirxrwsbO/J1qMER |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9416ebcac9caca96 |
|
VISUAL
aHash
|
fd0606060606fffb |
|
VISUAL
dHash
|
71ccecccecfc3b13 |
|
VISUAL
wHash
|
fd0606060606fffb |
|
VISUAL
colorHash
|
0e0000001c0 |
|
VISUAL
cropResistant
|
0001496161490152,96d6e8b084710f8e,c030330c3b531333,9cccecccccececec,5c8b26dececec646 |
• Threat: Phishing
• Target: Cryptocurrency investors
• Method: Impersonation and form submission
• Exfil: Account information
• Indicators: Domain name, request for PII.
• Risk: High
The attackers are attempting to harvest user credentials by presenting a fake sign-up form that looks similar to the legitimate website.
Pages with identical visual appearance (based on perceptual hash)