Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1539263B0B215AA3701E783C1F22657AB62A6C189DA27171123FCC3AD5FE5D56EC3314E |
|
CONTENT
ssdeep
|
384:C6oTAoNhoAm9WmINDDwExb0t59U8tYwts74DKaCJDvbUgTbglceFQsNTV:ujjA3INQoApXRIQgTbgl |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
928d6d3992d69369 |
|
VISUAL
aHash
|
00006e2e2e0e0000 |
|
VISUAL
dHash
|
bab2ccccdcdc270c |
|
VISUAL
wHash
|
0a1f7f7f7e6e0000 |
|
VISUAL
colorHash
|
38e00000000 |
|
VISUAL
cropResistant
|
f96397b34d0f8fcd,bab2ccccdcdc270c |
• Threat: Crypto Wallet Drainer
• Target: Cryptocurrency traders
• Method: Fraudulent airdrop claim
• Exfil: Wallet connection API
• Indicators: Recent domain, obfuscated JS
• Risk: Critical financial loss
The site uses malicious scripts to trigger a 'Connect Wallet' prompt in Web3 browsers, initiating a malicious transaction signature to drain the user's funds.
Promising exclusive rewards to 'reputable' users to bypass security skepticism.