Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13DC2693CB0473C775877C9C0F496AF19B0D6DB36C5280A59E7B69A582FCACE49931328 |
|
CONTENT
ssdeep
|
768:NZSW3RCCO+27Jt8kWkcklkoFm5LfVfLf1hLfINLfg7NtTzhBeC3D:aW3RCCOdt8kWkcklkoFm5LfVfLf1hLff |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ead5d5eaaa09152a |
|
VISUAL
aHash
|
ffff000001010101 |
|
VISUAL
dHash
|
0000961555155521 |
|
VISUAL
wHash
|
ffffff0101010199 |
|
VISUAL
colorHash
|
3a000000406 |
|
VISUAL
cropResistant
|
0000961555155521 |
• Threat: Cryptocurrency wallet phishing
• Target: Tonkeeper wallet users
• Method: Fake dashboard interface to deceive users
• Exfil: Obfuscated JavaScript detected
• Indicators: Domain mismatch, JavaScript obfuscation
• Risk: HIGH - Potential for credential and financial data theft
Pages with identical visual appearance (based on perceptual hash)