Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1227114F09990A73752D687D9EB32B77AF3E24146DF870226A6F883894797D41EC02860 |
|
CONTENT
ssdeep
|
48:nrC34Kgfci/Rk17jXXqOJeOyJ45/eeezwIenA2LK7EI8JUCl6IwR+IAuJV:nrCVg00GAOO45iwve7bCloQuT |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f3e34ec8c848e363 |
|
VISUAL
aHash
|
ffefe7ffffff0000 |
|
VISUAL
dHash
|
234c4d325a1a3010 |
|
VISUAL
wHash
|
bde2e3ebff000000 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
2b324d4d321a5a10,0000000000000000,ffdf6b693f3f3f3f,0830342832103008 |
• Ameaça: Phishing de carteira de criptomoedas
• Alvo: Usuários do Coinbase
• Método: Página falsa para conectar carteiras de criptografia, provavelmente levando ao roubo
• Exfil: Desconhecido, provavelmente comprometimento direto da carteira
• Indicadores: Incompatibilidade de domínio (server.cpanelmanager.com vs. coinbase.com), aviso de conexão de carteira
• Risco: CRÍTICO - Potencial de roubo imediato de criptomoedas
Pages with identical visual appearance (based on perceptual hash)
Found 5 other scans for this domain