Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16282E7F26200E4AF5613CFE4B47BB01DB04BF5AED9A5DC82D396ABA14BC5DD088DD502 |
|
CONTENT
ssdeep
|
384:GLzWWVxHk/iGUKtmH1Icd42NaxhmlM2mAjJNYbwKp/l1xgR0jBdWfB:GLzWWVxHk/zUKsH1Icd42NaDwkwa/fxy |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc8933cc6633d9cc |
|
VISUAL
aHash
|
0018181818180000 |
|
VISUAL
dHash
|
2432b2b2b2b20810 |
|
VISUAL
wHash
|
3c3c3838383830b0 |
|
VISUAL
colorHash
|
00007000000 |
|
VISUAL
cropResistant
|
8c2b335555332b8e,a61616464b5b1484,a981e9c981b18e8d,aa2aaa90d4a2b886,2432b2b2b2b20810 |
• Amenaza: Phishing
• Objetivo: Usuarios de Binance
• Método: Suplantación de identidad a través de una página de inicio de sesión falsa.
• Exfil: wss://nbstream.yshyqxx.com:443
• Indicadores: Dominio no coincidente, formulario de inicio de sesión, logo de Binance.
• Riesgo: Alto
The site uses a fake login form to collect user credentials.
The site uses the familiar Binance logo and login screen to trick users.
Pages with identical visual appearance (based on perceptual hash)
Found 6 other scans for this domain