Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B57386717A01742731AF91CFD12B1A0D51C2E7CFCA955EC9A5F04369ABF2C94BAC22E4 |
|
CONTENT
ssdeep
|
768:LAPfe+EN9/2xt6plwnGnead2jXHQB2uEnNNBAzoB5cO:LAXe+EN9/2xtUlxeakjXy9o0O |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
948e35744bde5a62 |
|
VISUAL
aHash
|
0f0f3f3d00020200 |
|
VISUAL
dHash
|
fc7ffd7986949493 |
|
VISUAL
wHash
|
3f1f7f3f42464600 |
|
VISUAL
colorHash
|
38000000180 |
|
VISUAL
cropResistant
|
fc7ffd7986949493 |
• Threat: Credential/Asset Harvesting
• Target: General Users/Crypto
• Method: Deceptive 'Asset Protection' landing page
• Exfil: JavaScript obfuscation for data interception
• Indicators: Recent domain, obfuscated code
• Risk: High
The site uses a deceptive security portal to entice users to connect wallets or provide account credentials.
Hiding malicious redirection or data exfiltration logic within encoded JavaScript strings.