Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FC13E67144C42B3F919343C8E3916A4BF39BC244E2768A5DF2EA8B1F56C5D48C86BB5C |
|
CONTENT
ssdeep
|
768:M0bPIiBwU9yquge41yI/dWB/tO/CheYr7K5Npn5leoTfYHI8gKN:M0bPIi6U9yqugeuF/oB1O/dXpfAHI8gU |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9416ebeac9caca94 |
|
VISUAL
aHash
|
fd06060606fffffb |
|
VISUAL
dHash
|
71ccecccec3c3333 |
|
VISUAL
wHash
|
fd060606060efff9 |
|
VISUAL
colorHash
|
0e000000180 |
|
VISUAL
cropResistant
|
0001496161c90162,96d6e8b094710f8e,c0381c2b33333303,ccccecccececccec,5b27d6cec6c7c7d7 |
• Threat: Phishing
• Target: Users interested in crypto investment
• Method: Impersonation through a website with a login form.
• Exfil: Potentially personal and financial information entered into the form.
• Indicators: JavaScript obfuscation, form requesting PII, unknown domain.
• Risk: High
The site uses a form to collect email and phone numbers, with the intent of using them for further attacks or selling them. JavaScript is obfuscated which may indicate additional malicious functionality
Pages with identical visual appearance (based on perceptual hash)