Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10673BA34D1500A3304C392C5EFF7672F51A5E729CE230EAE97F8831A6B8BD989F15925 |
|
CONTENT
ssdeep
|
1536:GA69shfa+nYBlApfEAoT6qg+3OiwGnnR/zwieO3jGWQZ+Wj4/hPl:jaDB6v8Wj4j |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8989f270b0cf66f2 |
|
VISUAL
aHash
|
5e383d3c1c003c01 |
|
VISUAL
dHash
|
98f2e3f2b0e0f055 |
|
VISUAL
wHash
|
7e3f3c381c007c8f |
|
VISUAL
colorHash
|
31206000000 |
|
VISUAL
cropResistant
|
98f2e3f2b0e0f055 |
• Threat: Phishing/Credential Harvesting
• Target: Cryptocurrency users
• Method: Fraudulent trading platform interface
• Exfil: Obfuscated JS-based submission
• Indicators: Obfuscated code, suspicious domain
• Risk: High
The site mimics a legitimate crypto exchange to lure users into submitting their login credentials.
Uses obfuscated scripts to hide the endpoint where credentials are sent.