Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B003A470D1492926B177D4D1E471936FB2A1C34CDB930B5897EC936AB6CACB1FE221C8 |
|
CONTENT
ssdeep
|
768:dKUS33gQS1CcuWCvQODcuWCvQOqzebbiGSMJaUVniJI3OASAIIzCj/F6byyY0fKW:03gQS1CcuWCvQODcuWCvQOxtW+eASAI+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc993366cc996666 |
|
VISUAL
aHash
|
0000181818000000 |
|
VISUAL
dHash
|
0008303030080000 |
|
VISUAL
wHash
|
bd5abd3cbd42a500 |
|
VISUAL
colorHash
|
38200040006 |
|
VISUAL
cropResistant
|
0008303030080000 |
• Threat: Crypto Drainer
• Target: Pump.fun users
• Method: Malicious dApp connection
• Exfil: WebSocket-based data harvesting
• Indicators: Obfuscated JS, suspicious domain
• Risk: Critical
The site uses social engineering to prompt a wallet connection, subsequently executing malicious transactions to empty assets.
Uses WebSockets to monitor session activity and extract metadata.
Pages with identical visual appearance (based on perceptual hash)