Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11DF272BE9255B837019387D2F8790746A3E9C247EA8215D6B3F9C38C4BC5CB4E97212D |
|
CONTENT
ssdeep
|
768:qK6h7EVfof+zEmbcmp0XBbNzU4UR6URvlKof:OGgf2Emgmp0xbNzU4UwU1lKof |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8ad4bbe5532c546c |
|
VISUAL
aHash
|
ff3f18000000030d |
|
VISUAL
dHash
|
dde9b536c8cbc349 |
|
VISUAL
wHash
|
ffffff000804032d |
|
VISUAL
colorHash
|
30006000080 |
|
VISUAL
cropResistant
|
000000000040ffff,8008c06d2d800080,70d8ccf4ecc4949c,000802d8d8c22000,ebf136cac8cbcb49 |
โข Threat: Phishing
โข Target: Crypto users
โข Method: Impersonation and Credential Harvesting
โข Exfil: http://web3orbit.com/
โข Indicators: Obfuscated Javascript, Suspicious domain, and Cryptocurrency branding
โข Risk: Critical
The site likely attempts to steal login credentials or wallet access information. The 'Connect Wallet' button is a clear indication of this.
The obfuscated Javascript is a likely candidate for the injection of malicious code, perhaps a keylogger or a trojan to steal crypto assets.
Found 1 other scan for this domain