Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B84265F7A0005A3F82D7C2EA7A5132BBA3A34345DAC616015AFA8B4E59F3F55DC0714A |
|
CONTENT
ssdeep
|
192:Nk44ieb1dHhg7nLf+BtDM4bp702s3QZExq78lQ:Nk44hbrHhgPcDMyf8lQ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bcb9439cc665b831 |
|
VISUAL
aHash
|
ffffffffff9f0000 |
|
VISUAL
dHash
|
25181a363634c0c8 |
|
VISUAL
wHash
|
ffcf8f9fdf000000 |
|
VISUAL
colorHash
|
0ee00000000 |
|
VISUAL
cropResistant
|
2f381a1a36263034,516559b6b4495141,000002e0c4c0c8c8 |
• Threat: Crypto Investment Scam
• Target: Financial/Crypto investors
• Method: Deceptive landing page with obfuscated JS for potential credential/wallet harvesting
• Exfil: JavaScript-based submission
• Indicators: Obfuscated JS code, unrealistic 'Zero lock-up' claims
• Risk: High - Potential financial theft
The site lures users into 'starting their journey', likely triggering a wallet connect prompt or account registration for data theft.
Used to evade simple static analysis of the landing page's form submission logic.