Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AB6254B69102A93F11F3C1D2A621AB3F72E6914DDA4B0B0653FC4B2D4BC6DA0FC25599 |
|
CONTENT
ssdeep
|
192:wVsBilI0IINBXf3myiCBdtE5kMEzmc8T5c3/7MNR3PZR/37:usBgxII/3m70DE9zW3jA3PDj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c68cb8b086cfe1bc |
|
VISUAL
aHash
|
ff000074266000ff |
|
VISUAL
dHash
|
2f34cbc4c4cc2340 |
|
VISUAL
wHash
|
ff000076767700ff |
|
VISUAL
colorHash
|
30000e40000 |
|
VISUAL
cropResistant
|
c029292f2f2929c4,0000000000000000,4133c8c4cccd2340 |
• Threat: Crypto Wallet Drainer
• Target: Cryptocurrency users
• Method: Social engineering via 'AI Trading' tool
• Exfil: JavaScript form/webhook submission
• Indicators: Obfuscated JS, rapid token sniping claims
• Risk: Critical financial loss
The site uses a deceptive interface to trick users into connecting their Web3 wallets. Once connected, malicious scripts attempt to prompt the user to sign a fraudulent transaction or approve token transfers.
Forms designed to capture wallet information or API keys under the guise of setting up an AI trading terminal.