Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AC31DFB10208AE2347B3D3C67E6663BA31D1C581EE4A274067F913E90BD6E6DDF4A047 |
|
CONTENT
ssdeep
|
24:hRfATQmnK56eFF5mnX1trtI6aU6OsW6Vc64OcPK370OGp9nGmhotRa:TYTK5Pa1QUPhfOkZ9GUaRa |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cfcd61939b31309a |
|
VISUAL
aHash
|
3838183c3c000000 |
|
VISUAL
dHash
|
6870706161162000 |
|
VISUAL
wHash
|
3c3c3c3c3c383030 |
|
VISUAL
colorHash
|
38007400000 |
|
VISUAL
cropResistant
|
6870706161162000 |
• Threat: Crypto Wallet Drainer
• Target: Cryptocurrency users
• Method: Malicious dApp 'Connect Wallet' request
• Exfil: Unauthorized smart contract interaction
• Indicators: Fake countdown, 'Connect wallet' CTA
• Risk: Critical asset loss
Prompts user to connect Web3 wallet to sign malicious transactions that transfer assets to the attacker's address.
Promises free rewards/tokens to lure victims into performing the transaction.