Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11CC273B02264103BA11796C76F66273936FBB1FED97B0104E7FD06949BEAC89EC23445 |
|
CONTENT
ssdeep
|
384:wDdWtqY+SAaLnGntU74CyZrwq/Z2ozcRYXOOyj71920SVV0PYJHYc1RcWyXja:QCAaLwM/ypw82KcRYXOb96KOYwaja |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92922d6de99696e2 |
|
VISUAL
aHash
|
03647c6c4000407e |
|
VISUAL
dHash
|
96cded8d926cd4d4 |
|
VISUAL
wHash
|
47447c7e60047e7e |
|
VISUAL
colorHash
|
38002000180 |
|
VISUAL
cropResistant
|
e8d8b2ccc9a2e6e8,96cded8d926cd4d4 |
โข Threat: Cryptocurrency phishing site
โข Target: BlackBull users and crypto enthusiasts
โข Method: Fake airdrop promotion to steal wallet credentials
โข Exfil: Potential data sent to unknown servers
โข Indicators: Domain mismatch, free rewards, urgent language
โข Risk: HIGH - Immediate wallet theft
The phishing site prompts users to connect their crypto wallets (e.g., MetaMask, Phantom) via buttons labeled 'Connect Wallet'. Once connected, the site may request token approvals or drain funds by exploiting smart contract interactions.
The site may deploy credential harvesting techniques to capture login credentials or OTPs, enabling account takeover or unauthorized access to financial platforms.
Obfuscated JavaScript file likely containing credential harvesting and wallet connection logic.
Pages with identical visual appearance (based on perceptual hash)