Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C14373529169963B21724BE9F76BAB96FF428086CCD3404FE1E9D35C1BE2CB1FC19214 |
|
CONTENT
ssdeep
|
1536:U2j0NgomuZeYxGv2IXr96y9g6+SjDxn6xDVc1qL:Uiqr96fDxGDVjL |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
de5e6961615c7492 |
|
VISUAL
aHash
|
80809c9cffffffff |
|
VISUAL
dHash
|
333c3c341c1c203c |
|
VISUAL
wHash
|
80808c9ceeeefee2 |
|
VISUAL
colorHash
|
070020001c0 |
|
VISUAL
cropResistant
|
333c3c341c1c203c |
โข Threat: Impersonation and Credential Harvesting
โข Target: MetaMask users
โข Method: Blog hosted on blogspot.com with content unrelated to MetaMask, likely redirecting to a phishing site or harvesting information.
โข Exfil: Potentially through blogspot search or other forms.
โข Indicators: Domain, content mismatch, obfuscation, form actions.
โข Risk: HIGH
The site uses a MetaMask related domain and impersonates a support site but talks about Robinhood issues to trick users into providing sensitive data, such as private keys, which can be stolen.
The site uses a free blogspot domain to host the content, a common tactic for phishing because it offers a degree of perceived trust.
Pages with identical visual appearance (based on perceptual hash)