Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D823D93118C86F2725D392C4B354A69FE395854CE27ACA56F6DBC31E1AC4E84CC3AF58 |
|
CONTENT
ssdeep
|
768:yMDud/NieKB0vAiuKlnOrIvGaDb8Eh9bdDXwwctK5JLjlQ03fo58Dxj3a8l0Wr7B:yMD2/NieKBqu4Or0z8EhfwwctK5JLjlN |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
946bb494ebb084f9 |
|
VISUAL
aHash
|
ff000000067e1e36 |
|
VISUAL
dHash
|
31f0c4d0ccccbccc |
|
VISUAL
wHash
|
ff180000767e7e76 |
|
VISUAL
colorHash
|
01000000030 |
|
VISUAL
cropResistant
|
0001012323890006,8494c0f4b0881e5a,a62466a424327236,71e0d4e0ccecbccc |
• Threat: Phishing
• Target: Cryptocurrency investors
• Method: Impersonation with account creation forms
• Exfil: Form submission, Javascript Obfuscation
• Indicators: Domain, forms, Javascript
• Risk: HIGH
The attackers are likely collecting user credentials through a signup form.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain