Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13BC2A4305486E97B048BB3E0A32A9B677790E344C257570A52FCC76E5FE2C94EC3A275 |
|
CONTENT
ssdeep
|
384:IutIl4oM8Vh4F5go2mXxQqf/u2g6m3E+I2i3rWRVumBUMf:IuDB2mlf/uHEyMrW31BUMf |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9234ebe914d2b761 |
|
VISUAL
aHash
|
0000060404ffffff |
|
VISUAL
dHash
|
96cc9cac9c232321 |
|
VISUAL
wHash
|
000006060fffffff |
|
VISUAL
colorHash
|
13001000180 |
|
VISUAL
cropResistant
|
a080e0b4b48080a0,a280e0b434a080b2,a080e0ba1ad88092,8a009898da380082,8023d4e4a4842180,1b00232b23230133,963ecc9c9cacac98,f2f272c8ccf4a0ce |
โข Threat: Phishing
โข Target: Cryptocurrency investors, German speakers
โข Method: Impersonation and data theft
โข Exfil: validation/thankyou.php
โข Indicators: Recent domain, form submission, urgency, high profit claim, obfuscation
โข Risk: High
The site uses a form to collect personal information (name, email, phone number) which will be used for malicious purposes, such as identity theft or further phishing attempts.
The site could be used as a front for a variety of malware infections.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain