Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12E33853650046ABB12C386C277B17B5FB3D9E246C747066A63E9C30D07D3E94DE3A962 |
|
CONTENT
ssdeep
|
768:sLeZSCL+InstWkmIK02DKfB5HLtC+vGh0U3yYv3EgrPiuN6Rq:18CL+IcRm82DurtVv2zUahf |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f648c9369136cb39 |
|
VISUAL
aHash
|
f0f0f0e6868686fc |
|
VISUAL
dHash
|
6426242c2c2c2c10 |
|
VISUAL
wHash
|
f0f0f0e6868686fc |
|
VISUAL
colorHash
|
03000008030 |
|
VISUAL
cropResistant
|
713113333333370c,54d8e6c470246458,6426242c2c2c2c10 |
• Threat: Cryptocurrency trading phishing kit.
• Target: Individuals interested in cryptocurrency trading.
• Method: Fake registration form steals personal and contact information.
• Exfil: Data sent to an unknown server.
• Indicators: Domain name unrelated to Ethereum, obfuscated JavaScript, forms present on the landing page.
• Risk: HIGH - Potential for identity theft and financial loss.
Pages with identical visual appearance (based on perceptual hash)