Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16DC2A3309186F937149BB3D0E376A74BB3919388E6035B1A53FD875D1FCAD40EC2A5A2 |
|
CONTENT
ssdeep
|
384:3SFwBJdtlI8nWbKyiE2W5TWeI1eIyKpzpi6mm5G1V2O7mBCqIOqrdlOdqf:3SFwXJxgVI0IvXmJ72V+aqf |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d234ebad14969569 |
|
VISUAL
aHash
|
0000040600fffdfd |
|
VISUAL
dHash
|
929f9cbc9c332321 |
|
VISUAL
wHash
|
0000060e0effffff |
|
VISUAL
colorHash
|
1b002000180 |
|
VISUAL
cropResistant
|
a080c068688080a2,a080c0b030a08092,a080a81a1aa080a2,0800189ada280008,0006686969699620,1b002b2329210103,923fde9c9cac9c98,4cb0f06060e02129 |
• Amenaza: Phishing
• Objetivo: Personas interesadas en el comercio de criptomonedas
• Método: Falsificación de plataforma de comercio
• Exfil: validation/thankyou.php (probablemente recopila información personal y financiera)
• Indicadores: Dominio reciente, envío de formulario, ofuscación de JavaScript, reclamos de altos rendimientos y oferta por tiempo limitado.
• Riesgo: ALTO
The attackers are attempting to collect user credentials by presenting a fake login/registration page.
Pages with identical visual appearance (based on perceptual hash)