Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BC42313850447E3B02A741E5BB3AA74BF3D1C196CE1B1B0452F883AD5FE6D59DC235A2 |
|
CONTENT
ssdeep
|
384:ZumFvCOx8kF8rXJ0keiVOMxVENuOPmwTW/EJ8:4mFvCO+S865PW/EO |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8e4eb171b24c9c6d |
|
VISUAL
aHash
|
0000301c0000ffff |
|
VISUAL
dHash
|
94686169552aaa1d |
|
VISUAL
wHash
|
0020383c00ffffff |
|
VISUAL
colorHash
|
31000038000 |
|
VISUAL
cropResistant
|
b20c4ba9ccd4d50a,a2a4a08686a080a2,55aaaa2255002c1d,9448606168512a2a |
⢠Threat: Crypto Phishing
⢠Target: Cryptocurrency users
⢠Method: Impersonation of a fake financial service
⢠Exfil: Unknown (JS obfuscation present)
⢠Indicators: Obfuscated JS, template-based site
⢠Risk: High
The site lures victims to provide login credentials or personal info through a deceptive 'Get started' flow.
Uses obfuscated JS to prevent analysis and evade detection filters.