Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T115522130A48A2B7B00C356E0BB746F5AF3D68384C7631B18A3F4879E5FD6D0ACD2A555 |
|
CONTENT
ssdeep
|
192:UCBB50/yt981C2Qork1WuCLQ9XfzAsVgCPz6Mc:Y/yt9814+cWukgr/+CPo |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9199583b7ab8bae0 |
|
VISUAL
aHash
|
0000ffffff000000 |
|
VISUAL
dHash
|
10d080b8cc559284 |
|
VISUAL
wHash
|
0000ffffffff0000 |
• Threat: Cryptocurrency mining scam impersonating Binance
• Target: Binance users interested in DeFi and mining
• Method: Warning message about impersonation as pretext for a phishing attempt
• Exfil: Unknown, likely credentials or crypto assets if user interacts with the site
• Indicators: New domain, brand impersonation, generic warning message
• Risk: HIGH - potential theft of crypto assets and/or credentials
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain