Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10C728470A4A2583F912B5AC1F5B07BAE60EAF30EDD5B0A14D3FC13EA5FD6C94E805125 |
|
CONTENT
ssdeep
|
384:WCzJzIOGcSToKTgnSwSSJo0JGe78yNKQl5HdSNSSLY/r9hezi1m2N1:tzJzI3cMfsnTS6FA8X4sRduSm6BgQj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
993476e2891fc8cb |
|
VISUAL
aHash
|
0000181818180000 |
|
VISUAL
dHash
|
bc8cb2b2b2b24c31 |
|
VISUAL
wHash
|
04c7181a7f18bdbd |
|
VISUAL
colorHash
|
30c000000c0 |
|
VISUAL
cropResistant
|
845d79767b193586,bc8cb2b2b2b24c31 |
โข Threat: Phishing
โข Target: Crypto wallet users
โข Method: Impersonation and credential harvesting
โข Exfil: wss://relay.walletconnect.org (potential)
โข Indicators: Wallet logos, form-based interface, obfuscated javascript.
โข Risk: HIGH
The site uses the logos and UI of legitimate wallets to trick users into connecting their wallets, likely requesting a seed phrase or private key after.
Pages with identical visual appearance (based on perceptual hash)