Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16113423760405A3F12D782C67BB43B4EF3DAD689CA93565667F8830D07C6E80CD31AA6 |
|
CONTENT
ssdeep
|
768:0ETm9C+I6hnVlbuVxkYsNjXTeTr/nmk6q:e0+IanVl6VnsXyPmkH |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b239cd4d361c3c47 |
|
VISUAL
aHash
|
00ffc7878787ffff |
|
VISUAL
dHash
|
231b0e2c2c3ec8a8 |
|
VISUAL
wHash
|
00cf87878703fef8 |
|
VISUAL
colorHash
|
07202030000 |
|
VISUAL
cropResistant
|
231b2e2c2c3ec8a8,0008046870702004,f0f5bcb9a36958c6 |
• Threat: Phishing
• Target: Cryptocurrency investors
• Method: Credential harvesting
• Exfil: Form data
• Indicators: Unrelated domain, forms, urgency tactic
• Risk: High
The site employs a web form designed to collect user data, with the ultimate aim of stealing passwords and personal details. The collected data can be used for financial crimes and identity theft.
The information harvested may be used in later spear phishing attempts, which are more targeted and thus more likely to succeed.
Pages with identical visual appearance (based on perceptual hash)