Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BFC1857472511B7F51C381F6F762ABAAF684C356C63B9748A2F9C2C50BC6C2ACE14290 |
|
CONTENT
ssdeep
|
96:RBqXmmyCekg3VJr945uH0kzbKWRAZt6ItarZeYp:RBqJle5X25c0QRU6p |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c0c03b3f3f3fc068 |
|
VISUAL
aHash
|
7070707070700000 |
|
VISUAL
dHash
|
a6e4e4c4c4e41b80 |
|
VISUAL
wHash
|
70fcfc7e7c7e0000 |
|
VISUAL
colorHash
|
31007000000 |
|
VISUAL
cropResistant
|
8080b217cf888280,80898855452559b8,84535b97974b5780,a6e4e4c4c4e41b80 |
• Threat: Phishing
• Target: Blockchain.com users
• Method: Impersonation and compensation scam
• Exfil: Unknown (Likely aims to steal credentials or crypto through a form)
• Indicators: Domain mismatch, claims of payouts, urgency.
• Risk: HIGH
The attackers are trying to mimic the look and feel of Blockchain.com to steal user's Bitcoin.
The site leverages users' trust and the promise of compensation to deceive them into providing information.
Pages with identical visual appearance (based on perceptual hash)