Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14583E73152502A3F65478FE4F7A4B36D21ABD39ED9078624E7BC13721BC6CE2ED26184 |
|
CONTENT
ssdeep
|
1536:901udIxLsD4AzgbCdkgcppKIj/7SAZHA8axY0maCLV:iuWxSIFNkq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8f98d3667332c698 |
|
VISUAL
aHash
|
fe3e3e1c00302020 |
|
VISUAL
dHash
|
70f0f07060616969 |
|
VISUAL
wHash
|
ff7f3e3c00303434 |
|
VISUAL
colorHash
|
30002e00000 |
|
VISUAL
cropResistant
|
70f0f07060616969 |
โข Threat: Crypto Wallet Drainer
โข Target: Cryptocurrency users
โข Method: Fake token airdrop/eligibility claim
โข Exfil: Web3 wallet connection/signature
โข Indicators: Extremely recent domain, high-pressure financial claims
โข Risk: Critical/Total asset loss
The site prompts users to connect their Web3 wallet under the guise of an airdrop, followed by malicious transaction signatures to empty funds.
Use of urgent, official-sounding 'eligibility' language to bypass user skepticism.