Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T105D112718A083A2E92335ED0EA7563AB62ABB37DF58F101095BD43F087C6F84C927585 |
|
CONTENT
ssdeep
|
96:T+fmKjKp+36BDLQRk1ByG/I83mb2zW+L6Sk1aq6vSm1OofPez:SfmKjKwkDsRMZ/v3TLicq6hZfPK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b3b38c8c9999b926 |
|
VISUAL
aHash
|
ff67e76e24180000 |
|
VISUAL
dHash
|
62cc4cd84c100000 |
|
VISUAL
wHash
|
ffe7e7ee66180000 |
|
VISUAL
colorHash
|
07007000000 |
|
VISUAL
cropResistant
|
62cc4cd84c100000 |
• Threat: Phishing
• Target: Cryptocurrency users
• Method: Impersonation of PaxSwap platform.
• Exfil: Unknown, likely to steal credentials and drain crypto wallets.
• Indicators: Free hosting, brand logo present.
• Risk: HIGH
The site impersonates PaxSwap's interface to trick users into connecting their wallets and entering their credentials. This could lead to account compromise and theft of crypto.
If users connect their wallets, the site could attempt to drain their funds by initiating malicious transactions.
Pages with identical visual appearance (based on perceptual hash)