Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13BC2A4305486E97B048BB3E0A32A9B677790E344C257570A52FCC76E5FE2C94EC3A275 |
|
CONTENT
ssdeep
|
384:IutIl4oM8Vh4F5go2mXxQqf/u2g6m3E+I2i3rWRVumBUMf:IuDB2mlf/uHEyMrW31BUMf |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9234ebe914d2b761 |
|
VISUAL
aHash
|
0000060404ffffff |
|
VISUAL
dHash
|
96cc9cac9c232321 |
|
VISUAL
wHash
|
000006060fffffff |
|
VISUAL
colorHash
|
13001000180 |
|
VISUAL
cropResistant
|
a080e0b4b48080a0,a280e0b434a080b2,a080e0ba1ad88092,8a009898da380082,8023d4e4a4842180,1b00232b23230133,963ecc9c9cacac98,f2f272c8ccf4a0ce |
• Amenaza: Phishing
• Objetivo: Inversores en criptomonedas, de habla alemana
• Método: Suplantación de identidad y robo de datos
• Exfil: validation/thankyou.php
• Indicadores: Dominio reciente, envío de formulario, urgencia, alta afirmación de ganancias, ofuscación
• Riesgo: Alto
The site uses a form to collect personal information (name, email, phone number) which will be used for malicious purposes, such as identity theft or further phishing attempts.
The site could be used as a front for a variety of malware infections.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain