Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C013C83108856F3B51A3D3CDA3605F0BE395858CE2B68589F5EAC31B66C4D95C82FF98 |
|
CONTENT
ssdeep
|
768:7LtH1CiIBC4q0slzm9akVNQaHYerDHYfXGO/Y0ltUShVvnUgYs1o4sF39yn:7L11CiIB5qZlzm9aEzYEHYf2O/NlJfXL |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9416eb4acbba9496 |
|
VISUAL
aHash
|
fd0006060600ffff |
|
VISUAL
dHash
|
61ccecccecec1933 |
|
VISUAL
wHash
|
ff0006060606ffff |
|
VISUAL
colorHash
|
130000001c0 |
|
VISUAL
cropResistant
|
002149616149014a,96d6e8b094710f8e,e0181a5b2c3b3313,ccccecccccecece0 |
• Threat: Phishing
• Target: Cryptocurrency investors
• Method: Form submission to steal data.
• Exfil: Unknown (likely email and phone, as well as any other data entered into the form)
• Indicators: Domain name, form requesting personal information, and obfuscation.
• Risk: High
The site's primary attack method is credential harvesting, where attackers try to steal user's PII via a form for future attacks.
The information harvested may be used to launch spear-phishing attacks against the user, customized to the users' interests and connections.
Pages with identical visual appearance (based on perceptual hash)