Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18481FC6240C4552B220B65C3AD227B59B6F3033DCB7B0D21F2FD06DAABE8F91D917825 |
|
CONTENT
ssdeep
|
96:hEuG/IiC9uto2STbisDIo3DDD0xT/XO80DL:UwiC9u83ia5D0xTfOL |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8c6457a5a8de87cc |
|
VISUAL
aHash
|
12003cdbdb3f3c3c |
|
VISUAL
dHash
|
e6c660b3b3cef0d4 |
|
VISUAL
wHash
|
12003cd1db3f7e3c |
|
VISUAL
colorHash
|
31001c00000 |
|
VISUAL
cropResistant
|
6dd6cec3b0ec3a1c,70e8d4b2b2295d71,71e9cc96ba296979,808013c4ccccea15,e6c660b3b3cef0d4 |
• Threat: Cryptocurrency reward scam phishing
• Target: Solana (SOL) users
• Method: Fake website offers a "Welcome Bonus" requiring users to connect their wallets, potentially leading to the theft of cryptocurrency.
• Exfil: Likely exfiltrating wallet credentials or initiating unauthorized transactions.
• Indicators: Newly registered domain, generic TLD (.biz), obfuscated JavaScript, and a misleading reward claim.
• Risk: HIGH - Potential for immediate cryptocurrency theft.
Pages with identical visual appearance (based on perceptual hash)