Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T115F31A343358793E656383E2F1E67725B17E834BC80F4814F37899B66789C99A823BD4 |
|
CONTENT
ssdeep
|
3072:dz0gg2M9EHXEeUnWSA1FpPLXa5H4znV/yNhg9+Tj/mN6ZXt1967+ph:dYqFUnWSA1FpPL+3OSXt1967+ph |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8da6359d86953d26 |
|
VISUAL
aHash
|
0210007e3c181800 |
|
VISUAL
dHash
|
e67172f061323008 |
|
VISUAL
wHash
|
7a38387f3d3c1c0c |
|
VISUAL
colorHash
|
38003000180 |
|
VISUAL
cropResistant
|
fefeff9f4ffffefe,e67172f061323008 |
• Ameaça: Phishing/Golpe HYIP
• Alvo: Usuários de criptomoedas
• Método: Coleta por JS ofuscado
• Exfil: Envio via JavaScript
• Indicadores: JS ofuscado, domínio recente
• Risco: Alto
Uses a fake login portal to capture user credentials or connect malicious dApps to drain crypto wallets.
Lures victims with fake investment returns to solicit direct crypto deposits.