Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1896274B2A214AA3B262387D9B371F79AFB418685C9D2018BD1F5D35C1FD2CB1EC15215 |
|
CONTENT
ssdeep
|
192:iUAdFbOrLcwtnAs/V5N0MJ81uH4pyBZcTBrVOdI:IvCrJnAs/V5N0o81E4pUIBBmI |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fe7e61e1809e9684 |
|
VISUAL
aHash
|
80809c9effffffff |
|
VISUAL
dHash
|
3803343438202024 |
|
VISUAL
wHash
|
8000049cffcdcfc7 |
|
VISUAL
colorHash
|
070020001c0 |
|
VISUAL
cropResistant
|
3803343438202024,4101499393614101 |
• Amenaza: Suplantación de identidad
• Objetivo: Usuarios de MetaMask
• Método: Blogspam con contenido potencialmente malicioso.
• Exfil: Probablemente cualquier dato recopilado a través de enlaces maliciosos.
• Indicadores: dominio Blogspot, suplantación de marca
• Riesgo: ALTO
The attacker creates a website with a domain name that closely resembles the brand to deceive users.
The content appears to be a blog regarding a legitimate topic to build trust, before including malicious links.
Found 3 other scans for this domain