Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16E1220B55082AB7F1283C3D0627A5B1AF1D1E346CB9B971AA2FC135B1FC2CD2CD52158 |
|
CONTENT
ssdeep
|
96:nwDhpAgqFyrCKiFg8IsdJbx/pTUX9NADiYY5UuNHMbg+Hh+Hyxi+HwA/+X+A+iaO:K/JIRKiFXt3V/09N/RNkgmhmdmZQVoEV |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c909f6827629fd29 |
|
VISUAL
aHash
|
3c3c19193e7e7e84 |
|
VISUAL
dHash
|
69693373dcd49228 |
|
VISUAL
wHash
|
343c19116f7e7ca4 |
|
VISUAL
colorHash
|
13019000200 |
|
VISUAL
cropResistant
|
8001b2c8cc040080,69693373dcd49228 |
• Threat: Cryptocurrency wallet phishing
• Target: Users of Pump Fun and Padre, Solana ecosystem users
• Method: Attempts to steal cryptocurrency wallet credentials by prompting users to connect their wallets
• Exfil: Likely exfiltrates wallet keys to an attacker-controlled server
• Indicators: New domain, obfuscated Javascript, unusual TLD, requests wallet connection
• Risk: CRITICAL - Potential for immediate crypto asset theft