Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1711308202221735F6C330F79F385B06AC1AFD344EAA698ADF394525234D2974CB7799A |
|
CONTENT
ssdeep
|
768:6hFYLAn7n0NXuefT6nP8PJs1LGbPDPrPrAPLODPVPJFBD5EbQSFecnRiEQ5hQ2iq:6hFYLAn7n0JuefT6hGUOPTD5EbQSFeco |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b332cccc3333ccc6 |
|
VISUAL
aHash
|
efffc7c7c7ffefff |
|
VISUAL
dHash
|
1d160c8d8d1e1e5c |
|
VISUAL
wHash
|
01c3c7c7c7c3c387 |
|
VISUAL
colorHash
|
07006000000 |
|
VISUAL
cropResistant
|
1d160c8d8d1e1e5c,96f979f47833e4f4 |
โข Threat: Phishing
โข Target: Exodus Wallet Users
โข Method: Impersonation through a Gitbook page
โข Exfil: Unknown (due to obfuscation and form submission)
โข Indicators: Domain mismatch, Gitbook hosting, JavaScript form submission, obfuscation.
โข Risk: High
The attacker likely aims to steal Exodus login credentials. The page mimics the appearance of Exodus, and probably has a form to collect username/password, which the JavaScript submits.
Pages with identical visual appearance (based on perceptual hash)
Found 5 other scans for this domain