Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DBF1DD73C89BADF3166BB1C095231B7634C18706F95B6B255AFC028C67E9C49CE33A19 |
|
CONTENT
ssdeep
|
48:0VBTNmTNMJaJ67zUY85Qey18QayZoqQbqqEtHrwVGJAn7WsvuHUNIHL3d9d54PGF:ME6JJZdJAnKs7CjnZP/ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b6042f7ac0ff143a |
|
VISUAL
aHash
|
0301067fcf8485c1 |
|
VISUAL
dHash
|
ae6d9cac8d0d0d17 |
|
VISUAL
wHash
|
0323077fcf8785c3 |
|
VISUAL
colorHash
|
30003400008 |
|
VISUAL
cropResistant
|
ae6d9cac8d0d0d17 |
โข Threat: Cryptocurrency scam
โข Target: Solana users
โข Method: Claiming rewards to steal crypto
โข Exfil: Unknown, likely to a wallet address
โข Indicators: New domain, unrelated domain, reward claims.
โข Risk: HIGH
The site is attempting to trick users into thinking they can claim rewards. The user is then likely prompted to enter their wallet information to claim a reward, which allows the attacker to steal the crypto.
The site uses social engineering tactics like offering rewards and using the Solana branding to make it appear legitimate.
Pages with identical visual appearance (based on perceptual hash)